Impact
The vulnerability is a missing authorization issue in the Live sales notification for WooCommerce plugin. An attacker can bypass configured access controls and retrieve sale notifications that may contain sensitive information about customers and transactions.
Affected Systems
The issue affects PI Web Solution Live sales notification for WooCommerce from any earlier build up to version 2.3.49. WordPress sites running this plugin within that version range are vulnerable.
Risk and Exploitability
The CVSS base score is 5.3, indicating a moderate risk. The EPSS score is less than 1 percent, suggesting a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Likely exploitation requires access to the WordPress administrative interface or an authenticated user account with insufficient role restrictions; the attacker could read notification data, possibly exposing personal or payment details.
OpenCVE Enrichment