Impact
This vulnerability allows an unauthenticated attacker to bypass access controls within the Word WooCommerce plugin. The flaw can enable the attacker to view or modify deposit and partial payment order details. The weakness is identified as a classic authorization bypass, aligned with CWE‑862.
Affected Systems
The flaw affects the MagePeopleTeam Deposits and Partial Payments for WooCommerce plugin, versions 3.1.0 and earlier. Hosts running WordPress with this plugin installed before the release of the patch (at least version 4.0.1) are at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is < 1%, indicating a very low but non‑zero probability of exploitation. The likely attack vector is through web requests to the plugin’s endpoints without authentication. If exploited, an attacker could gain unauthorized access to order and payment data, potentially altering transaction details or accessing customer information.
OpenCVE Enrichment