Impact
The vulnerability originates from an authorization check failure on a REST endpoint within the Integration for Epos Now and WooCommerce WordPress plugin. An attacker who can access the endpoint can retrieve the Action Scheduler queue, including the queued tasks and their arguments, which expose order identifiers. When WooCommerce’s deferred emails feature is enabled, the arguments also contain plaintext passwords for newly registered customers. This direct exposure breaches confidentiality and could allow credential theft or account takeover.
Affected Systems
WordPress sites that have the Integration for Epos Now and WooCommerce plugin installed in any version before 4.11.2 (no lower bound specified), and that have WooCommerce enabled with the deferred emails feature for email notifications.
Risk and Exploitability
The attack vector is unauthenticated access to a REST API endpoint, requiring no user credentials or special privileges. Because the endpoint returns sensitive data, the risk to confidentiality is high. The exploit is straightforward: an external actor can issue a simple HTTP request to the unsecured endpoint. While EPSS data is not available and the vulnerability is not listed in KEV, the disclosure of plaintext passwords indicates a serious security issue that could be leveraged in a broader attack chain. The CVSS score of 5.9 indicates a moderate overall severity.
OpenCVE Enrichment