Impact
Improper validation of the quantity field in the Calliko Bonus for Woo WordPress plugin can allow attackers to manipulate inputs and access functionality that should be restricted by access control lists. The flaw can enable an attacker to submit or alter requests for features otherwise reserved for privileged users, potentially leading to unauthorized actions such as placing orders or processing refunds without proper authorization.
Affected Systems
The vulnerability exists in the Bonus for Woo plugin from any version through 7.6.6. It affects WordPress installations that have this plugin version installed, regardless of the WordPress core version. The vendor is Calliko and the product is the Bonus for Woo paid‑coupons plugin.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation. The flaw is not listed in the CISA Known Exploited Vulnerabilities catalog. The most likely attack vector is a crafted web request sent to the plugin’s endpoint, exploiting the lack of proper ACL checks. While no confirmed public exploits are known, the combination of input manipulation and missing access control represents a non‑negligible risk if attackers identify an endpoint to target.
OpenCVE Enrichment
EUVD