Impact
The vulnerability is a missing authorization control in the CoderPress Commerce Coinbase For WooCommerce WordPress plugin. It allows an attacker to exploit incorrectly configured access control security levels, enabling unauthorized interaction with plugin functions that should be protected and potentially misuse of the plugin’s features.
Affected Systems
Affected systems include the WordPress plugin CoderPress Commerce Coinbase For WooCommerce in all versions up to and including 1.6.6. No other products or integrations are listed as impacted.
Risk and Exploitability
The CVSS score of 7.5 classifies the issue as high severity, yet the EPSS score of less than 1% indicates a low likelihood of exploitation in the near term. The plugin is not part of the CISA KEV catalog. While the description does not specify the exact attack vector, it is inferred that a malicious user could reach the vulnerable functionality through the WooCommerce admin interface or public endpoints that lack proper authentication checks.
OpenCVE Enrichment