Impact
The advanced-customized-prompts plugin does not validate user capability, ownership, or nonce checks when updating WooCommerce order item metadata for a supplied order. As a result, any authenticated user—including a subscriber—can alter custom metadata for orders belonging to other customers. This lack of verification can lead to unauthorized changes to order data, violating data integrity and potentially compromising confidentiality of order information. The flaw is an example of a CWE-639 authorization bypass through user-controlled key, and based on the description it is inferred that it does not allow remote code execution or denial of service.
Affected Systems
WordPress sites that have installed any version of the advanced-customized-prompts plugin up to and including version 1.0.1 are vulnerable. The vulnerability exists irrespective of other plugins or theme components.
Risk and Exploitability
Exploitation requires only a logged-in WordPress account; the attacker can submit a request to rewrite order-item metadata without needing elevated privileges. The EPSS score of < 1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation to date. The impact is confined to data integrity and confidentiality of WooCommerce orders. The CVSS score of 4.3 indicates a medium severity assessment.
OpenCVE Enrichment