Impact
A missing authorization check in the ShopMagic plugin for WordPress lets an attacker access protected features without proper credentials. The flaw is a classic example of a broken access control weakness, catalogued as CWE-862. Attackers could exploit the vulnerability to retrieve or manipulate data meant for authenticated users, potentially compromising confidentiality or integrity of the e‑commerce site.
Affected Systems
The vulnerability affects the ShopMagic "shopmagic‑for‑woocommerce" plugin provided by wpdesk for WordPress installations. All released versions up to and including 4.7.2 are susceptible, as the issue exists in the code base until the fix is applied in a later release.
Risk and Exploitability
The CVSS base score of 5.3 indicates a moderate severity, with the exploit requiring some level of access to the WordPress site. The EPSS suggests that the probability of exploitation is lower than 1%, and the flaw is not listed in the CISA KEV catalog. Likely attack vectors involve sending specially crafted HTTP requests to the plugin’s endpoints, or leveraging an authenticated session to elevate privileges, though explicit prerequisites are not detailed in the description.
OpenCVE Enrichment