Impact
An authenticated attacker with Store Manager privileges can trigger the ec_ajax_save_page_default_options AJAX action, which loops over every key sent in the POST payload and writes each to the WordPress options table without restriction. By setting options such as default_role to administrator and enabling user registration, the attacker can later create a new account that receives administrator rights, effectively elevating their privileges. This flaw arises from missing input validation and improper authorization checks (CWE‑269).
Affected Systems
WordPress sites that have the Levelfourstorefront Shopping Cart & eCommerce Store plugin version 5.9.3 or earlier installed. These versions are vulnerable when the plugin is present on the site; users with the wpec_manager role, or any higher capability, are impacted.
Risk and Exploitability
The CVSS score of 7.2 reflects a moderate to high severity. EPSS is not available, so the probability of exploitation cannot be quantified. The vulnerability is not currently listed in CISA’s KEV catalog, indicating no known widespread exploitation at this time. The likely attack vector is an authenticated web request to the plugin’s AJAX endpoint, and the attacker does not need any special network access beyond normal site privileges.
OpenCVE Enrichment