Impact
The Product Configurator for WooCommerce WordPress plugin before version 1.7.3 fails to perform any authorization or post‑status checks before returning product data through a public AJAX action named pc_get_data. An attacker can supply a product ID and receive sensitive product attributes such as title, price, weight, stock status, and configurator option pricing or SKUs, even when the product is marked private or draft. This bypasses the WordPress post‑visibility controls and results in a confidentiality breach.
Affected Systems
Any WordPress site that installs Product Configurator for WooCommerce and uses a version older than 1.7.3 is affected. The extension is listed under the vendor "Unknown" and the plugin name "Product Configurator for WooCommerce"; no additional vendor or product details are provided.
Risk and Exploitability
The vulnerability is exploitable by anyone with unauthenticated HTTP access to the site, making the attack vector remote and straightforward. Although no EPSS score is available, the lack of authentication checks indicates a high potential for exploitation. The issue is not currently listed in the CISA KEV catalog, but the data exposure severity warrants immediate attention.
OpenCVE Enrichment