Impact
The Bonanza – WooCommerce Free Gifts Lite plugin contains a missing capability check in the xlo_optin_call() function, which is a CWE-862 Broken Access Control flaw. Authenticated WordPress users with Subscriber-level or higher permissions can invoke the function to set the opt‑in status to success. This does not allow code execution but enables an attacker to alter the plugin’s configuration state, potentially changing how free gifts are presented or awarded and thereby compromising the integrity of promotional data.
Affected Systems
The vulnerability affects WordPress sites that have the Bonanza – WooCommerce Free Gifts Lite plugin installed at any version up to and including 1.0.0, released by Amans2k.
Risk and Exploitability
The CVSS score of 4.3 reflects moderate severity, while the EPSS score being less than 1% indicates a low likelihood of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Because the issue requires a logged‑in user with at least Subscriber rights, the attack vector is restricted to authenticated users, limiting the potential impact to sites that mismanage user roles or have overly permissive Subscriber capabilities.
OpenCVE Enrichment
EUVD