Impact
The vulnerability is a missing authorization flaw that allows an attacker to perform actions normally restricted to privileged users. Because the flaw stems from incorrectly configured access control security levels, an unauthorized user could manipulate product bundle settings or access sensitive configuration data. The weakness is categorized as CWE-862, indicating improper restriction of privileges.
Affected Systems
Any WordPress installation that uses the YITH WooCommerce Product Bundles plugin version 2.29.0 or earlier is affected. The issue applies to all releases from the earliest version through 2.29.0. Users employing newer releases such as 2.30.0 or higher are not impacted.
Risk and Exploitability
The CVSS score of 5.3 reflects a moderate severity that can be leveraged by individuals who can reach the plugin’s administrative endpoints. Since the EPSS score is not available and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, the current exploitation probability appears low. Nonetheless, the attack path requires only that an attacker identify the relevant administrative interface, making the vulnerability somewhat easy to target once the target is known.
OpenCVE Enrichment