Impact
A missing authorization check in the Printcart Web to Print Product Designer for WooCommerce plugin exposes the product designer interface to users without proper credentials. The vulnerability allows any visitor to access the designer page and view its publicly exposed configuration options. The impact is limited to information exposure through the designer interface; the CVE description does not indicate that further system compromise or data modification is possible.
Affected Systems
All WordPress installations using Printcart Web to Print Product Designer for WooCommerce version 2.4.8 or earlier are affected. This includes every release from the initial version up to and including 2.4.8. No specific WordPress version or additional plugin configuration is required for the flaw to be present.
Risk and Exploitability
The CVSS score of 4.3 classifies the issue as moderate severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. An attacker can exploit the flaw by making standard HTTP requests to the designer URLs without authentication, indicating a remote web-based attack vector that can be executed from any network connected to the site.
OpenCVE Enrichment
EUVD