Impact
A flaw in the Automattic WooCommerce plugin caused incorrect privilege assignment, allowing users with certain roles to gain elevated permissions beyond their intended level. This can let an attacker modify store settings, view sensitive data, or perform actions normally restricted to administrators. The weakness is classified as CWE‑266. Because elevated privileges can be achieved, the attacker can compromise the confidentiality, integrity, and availability of the e‑commerce site.
Affected Systems
WordPress sites running the WooCommerce plugin with any version from 9.8.0 up to and including 11.1.2 are affected. This includes the standard default installation as well as any custom configurations that install those legacy plugin versions.
Risk and Exploitability
The CVSS score of 7.2 indicates high severity. EPSS data is not available, and the vulnerability is not currently listed in the CISA KEV catalog. The most likely attack vector requires authenticated access with a role that possesses default shop‑manager capabilities; the attacker then exploits the faulty privilege assignment logic to elevate privileges. Once elevated, the attacker can exploit the site’s full administrative functionality. The lack of remote exploitation data means that immediate patching is recommended without waiting for any exploit activity to surface.
OpenCVE Enrichment