Impact
The Ibtana – Ecommerce Product Addons plugin contains a missing authorization check on the 'iepa_use_gt_editor' AJAX endpoint, allowing an attacker to modify or delete arbitrary post meta entries by manipulating the 'iepa_builder' key. This flaw can change plugin settings, pricing data, or other sensitive configurations, thereby compromising data integrity and potentially enabling further exploitation. The vulnerability is identified as a missing authorization weakness (CWE‑862).
Affected Systems
WordPress installations that have the vowelweb Ibtana – Ecommerce Product Addons plugin at any version up to and including 0.4.7.7 are affected. All earlier releases share the same vulnerability because the authorization check is absent in the code base used by these versions.
Risk and Exploitability
With a CVSS score of 5.3, the flaw ranks as medium severity. The EPSS score is less than 1% and the issue is not listed in CISA KEV, indicating that widespread exploitation is unlikely at present. However, exploitation requires an authenticated WordPress account with at least Subscriber-level privileges, so an attacker who compromises a legitimate user account or acquires credentials can trigger the attack. Due to the reasonable attack vector and the impact on configuration data, system administrators should consider the risk moderate and treat the vulnerability as a potential entry point for broader compromise if the compromised account has higher privileges.
OpenCVE Enrichment