Impact
A missing authorization check in the WebToffee Product Feed for WooCommerce plugin allows users to exploit incorrectly configured access control security levels. This flaw enables unauthorized parties to use plugin functionality that should be restricted, potentially exposing or manipulating product feed data that is critical for e‑commerce operations. The weakness is classified as a broken access control vulnerability.
Affected Systems
The vulnerable plugin is WebToffee Product Feed for WooCommerce. Any installation of the plugin with a version number of 2.3.1 or earlier is affected.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate impact, but the EPSS score is below 1% and the vulnerability has not been listed in the CISA KEV catalog, suggesting a low likelihood of widespread exploitation at this time. Based on the description, it is inferred that the flaw can be exploited remotely through web requests to the plugin’s administrative endpoints, requiring an attacker with either access to the WordPress admin interface or the ability to craft specific requests to the vulnerable plugin. Given the access control weakness, an adversary could gain unauthorized read or write capabilities within the plugin’s domain.
OpenCVE Enrichment