Impact
The TikTok Business WordPress plugin contains an authorization bypass that allows an attacker to overwrite the merchant’s stored TikTok integration access token. The plugin fails to verify that the caller is authorized before updating the token, and thus a crafted request that supplies a valid TikTok OAuth auth_code can replace the original access token in wp_options. This gives the attacker control over the site’s TikTok Business and product catalog integration, potentially allowing access to business listings, advertisements, and related data.
Affected Systems
WordPress sites running the TikTok Business plugin version 1.4.1 or older are affected. The vulnerability applies to all releases of the plugin up to and including 1.4.1.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact, while the EPSS score of less than 1% suggests exploitation is unlikely at present and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to possess a valid TikTok OAuth auth_code for the merchant’s app. The likely attack vector is a crafted HTTP request that bypasses the plugin’s authorization checks and submits the auth_code, causing the token to be overwritten in the database.
OpenCVE Enrichment