Impact
The vulnerability in Webkul Bagisto allows a remote attacker to delete customer items through the Customer Item Deletion Endpoint because the system lacks proper authorization checks. This improper access control exposes the application to unauthorized data modification and loss, compromising data integrity. The weakness is classified as CWE‑266 and CWE‑284.
Affected Systems
Webkul Bagisto versions up to and including 2.4.4 are affected. Any deployment of these versions that has not received the vendor’s security update remains susceptible to exploitation.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate risk. The exploit is publicly available, and the attack can be launched remotely without requiring special privileges. With no EPSS score available and the vulnerability not listed in the CISA KEV catalog, the likelihood of widespread exploitation is currently limited; however, the presence of a publicly known exploit warrants timely remediation.
OpenCVE Enrichment