Impact
A missing authorization flaw in the Advanced Product Fields (Product Addons) for WooCommerce plugin allows attackers to bypass configured access control levels, potentially accessing privileged plugin functions without permission. This weakness can enable an unauthorized user to perform actions that are intended only for users with higher privileges, compromising data confidentiality and integrity for the WordPress site. The flaw is classified as CWE-862 (Missing Authorization).
Affected Systems
The vulnerability affects the Wombat Plugins Advanced Product Fields (Product Addons) for WooCommerce from unknown earliest release through version 1.6.18 inclusive. Any WordPress site running a version of this plugin in that range is susceptible.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is below 1%, suggesting a low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Attackers likely need to send authenticated or unauthenticated HTTP requests to plugin endpoints that lack proper ACL checks. The primary attack vector is network-based through the WordPress site’s front‑end or back‑end interfaces.
OpenCVE Enrichment