Impact
The vulnerability is a missing authorization flaw in the TaxCloud for WooCommerce plugin for WordPress that enables attackers to bypass configured access control settings. This flaw, identified as CWE‑862, gives unauthorized parties the ability to read or manipulate tax data stored by the plugin, potentially compromising the integrity and confidentiality of e‑commerce transactions.
Affected Systems
WordPress sites running the TaxCloud for WooCommerce simple‑sales‑tax plugin with a version of 8.3.8 or earlier are affected. The issue applies to all deployments of the plugin where access control levels are improperly configured.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, and the EPSS score of less than 1% suggests a low likelihood of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. While the exact attack vector is not detailed in the advisory, the missing authorization flaw could be exploited by attackers who can reach the plugin’s administrative endpoints, potentially without requiring credentials, depending on the configuration of the WordPress environment.
OpenCVE Enrichment