Impact
The vulnerability is an unauthenticated broken access control flaw that allows an attacker to bypass authorization checks and access restricted data or functionality within the SureCart WordPress plugin. Because the check is missing, an attacker could potentially retrieve or modify sensitive transaction information, view user details, or alter payment orders, thereby impacting confidentiality, integrity, or availability of e‑commerce operations.
Affected Systems
All installations of the SureCart WordPress plugin up to and including version 4.6.2 are affected. The flaw exists within the plugin’s back‑end components that manage cart and checkout processes on WordPress sites.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. EPSS is not available, and the vulnerability is not listed in CISA KEV. Attackers can exploit the issue over the web without authentication, likely by sending crafted HTTP requests to administrative endpoints that the plugin exposes. The lack of any existing active exploit evidence suggests a low to moderate likelihood of exploitation at present, but the unauthenticated nature and potential impact warrant timely remediation.
OpenCVE Enrichment