Impact
The Facebook for WooCommerce WordPress plugin contains a missing authorization flaw that lets users dismiss or manipulate site‑wide notices without proper authentication. This lack of access control can result in unauthorized changes to administrative notifications, potentially obscuring important site messages.
Affected Systems
WordPress sites that have installed the Facebook for WooCommerce plugin version 3.5.7 or earlier are affected. The vulnerability applies to any instance where that plugin version is active.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity, and the EPSS score of less than 1% suggests a very low likelihood of recent exploitation. The flaw is not listed in the CISA KEV catalog. The description indicates that the notice‑dismissal functionality can be accessed without authentication. Based on that description, the likely attack vector is remote HTTP requests targeting the notice‑dismissal endpoint, which an attacker could send without requiring login credentials.
OpenCVE Enrichment