Impact
The flaw is a missing authorization check that permits users to access protected parts of the Booster for WooCommerce plugin without proper permissions. This missing authorization is a classic privilege escalation flaw (CWE-862) and could allow an attacker to read or modify e‑commerce data, impacting confidentiality, integrity, and potentially availability of the store.
Affected Systems
The vulnerability affects the Pluggabl Booster for WooCommerce plugin (also known as woocommerce‑jetpack) on WordPress installations. All versions up to, but not including, 7.11.3 are susceptible. Users should verify whether their site is running any version prior to 7.11.3 and replace the plugin if so.
Risk and Exploitability
The EPSS score of less than 1% suggests that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. However, because the flaw allows unauthorized access, the potential impact is high if an attacker can reach the affected components. The attack vector is inferred to be through authenticated user levels that mistakenly have elevated privileges, or via misconfigured access controls; no direct remote code execution is described.
OpenCVE Enrichment