Impact
This vulnerability stems from a missing authorization check in the soporteblue Plugin BlueX for WooCommerce. The incorrect access control allows an attacker to exploit functions that should be restricted to privileged users. By sending specially crafted requests, an unauthorized user could gain access to administrative features and potentially modify or delete e‑commerce data, harming confidentiality and integrity of the store.
Affected Systems
The affected product is the soporteblue Plugin BlueX for WooCommerce. Versions from the earliest available through 3.1.6 are impacted. The plugin is used within WordPress sites that rely on WooCommerce for online sales.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.3, indicating moderate to high severity. The EPSS score is below 1 %, suggesting a low probability of exploitation at this time, and it is not currently listed in the CISA KEV catalog. Nevertheless, because the flaw permits unauthorized access to critical shop functions, attackers could potentially alter orders or manage product data. Remote exploitation via the web interface is likely, and the attack requires only publicly reachable endpoints without special credentials.
OpenCVE Enrichment