Impact
The WordPress Kit (formerly ConvertKit) for WooCommerce plugin has a missing authorization check that allows users to exploit incorrectly configured access control security levels. An attacker can gain unauthorized access to administrative functions of the plugin, enabling them to modify settings, inject content, or potentially exfiltrate data that should be protected by higher privilege levels. This results in a loss of integrity for plugin configuration and possible disclosure of sensitive information, depending on the data handled by the plugin.
Affected Systems
Any WordPress installation that uses Kit (formerly ConvertKit) for WooCommerce plugin version 2.2.0 or earlier is affected. The vulnerability applies across all environments where the plugin is enabled, regardless of the server configuration or additional security plugins.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, so the current probability of exploitation is unclear. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is an authenticated user or a user with elevated privileges on the WordPress site interacting with the plugin’s administrative interface or exposed API endpoints. No additional prerequisites such as network-level access or injection vectors are specified in the provided data.
OpenCVE Enrichment