Description
Missing Authorization vulnerability in Vollstart Serial Codes Generator and Validator with WooCommerce Support serial-codes-generator-and-validator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Serial Codes Generator and Validator with WooCommerce Support: from n/a through <= 2.8.2.
Published: 2025-12-31
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw that allows users to access or manipulate serial code functionalities without proper privileges. It enables attackers to view, generate, or alter serial codes normally restricted to privileged users, potentially compromising product licensing or customer data. This weakness is identified as CWE-862, representing improper authorization controls.

Affected Systems

Vollstart’s Serial Codes Generator and Validator with WooCommerce Support plugin versions up to and including 2.8.2 are affected. The vulnerability applies broadly across all installations of this plugin where access controls are insufficiently enforced.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate severity, and the EPSS score of less than 1% suggests a very low likelihood of widespread exploitation at this time. The vulnerability is not listed in the CISA KEV catalog, implying no known active exploitation reports. Based on the description, the attack vector is inferred to involve sending crafted HTTP requests to the plugin’s administrative or public endpoints that are supposed to be protected by authentication. An attacker with basic access to the site could exploit this flaw without additional prerequisites, but successful exploitation would likely require the plugin to be installed and the server to expose vulnerable endpoints.

Generated by OpenCVE AI on April 29, 2026 at 18:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the plugin to a version newer than 2.8.2 once an official patch is released.
  • Restrict access to the plugin’s administrative interfaces to users with administrative capabilities only.
  • If the plugin is no longer necessary, remove or disable it entirely to eliminate the attack surface.

Generated by OpenCVE AI on April 29, 2026 at 18:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Vollstart Serial Codes Generator and Validator with WooCommerce Support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Serial Codes Generator and Validator with WooCommerce Support: from n/a through 2.8.2. Missing Authorization vulnerability in Vollstart Serial Codes Generator and Validator with WooCommerce Support serial-codes-generator-and-validator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Serial Codes Generator and Validator with WooCommerce Support: from n/a through <= 2.8.2.
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 05 Jan 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Jan 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Vollstart
Vollstart serial Codes Generator And Validator With Woocommerce Support
Wordpress
Wordpress wordpress
Vendors & Products Vollstart
Vollstart serial Codes Generator And Validator With Woocommerce Support
Wordpress
Wordpress wordpress

Wed, 31 Dec 2025 14:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Vollstart Serial Codes Generator and Validator with WooCommerce Support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Serial Codes Generator and Validator with WooCommerce Support: from n/a through 2.8.2.
Title WordPress Serial Codes Generator and Validator with WooCommerce Support plugin <= 2.8.2 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Vollstart Serial Codes Generator And Validator With Woocommerce Support
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:01.293Z

Reserved: 2025-10-07T15:34:56.057Z

Link: CVE-2025-62091

cve-icon Vulnrichment

Updated: 2026-01-05T15:40:22.479Z

cve-icon NVD

Status : Deferred

Published: 2025-12-31T15:15:52.300

Modified: 2026-04-23T15:34:31.270

Link: CVE-2025-62091

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T18:15:17Z

Weaknesses