Impact
The vulnerability resides in the WooCommerce Cart Abandonment Recovery plugin versions below 2.1.0 and allows an attacker with shop manager privileges to elevate their privileges. This flaw is rooted in improper access control, as identified by CWE-266, enabling unauthorized use of privileged functions. An attacker could gain higher level permissions within the WordPress installation, potentially leading to full site compromise or unauthorized modifications of store data.
Affected Systems
Brainstorm Force’s WooCommerce Cart Abandonment Recovery plugin is affected when its version is older than 2.1.0. Sites running any of these legacy plugin editions and using WordPress are at risk; no other vendors or products are listed as impacted.
Risk and Exploitability
The CVSS score of 7.2 indicates a high severity level for this privilege escalation. The EPSS score of less than 1% suggests that while exploitation is technically possible, it is considered unlikely under current threat conditions. This vulnerability is not present in the CISA KEV catalog. Exploitation would require an attacker to be authenticated with shop manager rights, after which they could exploit the flaw to obtain higher privileges. The attack vector is presumed to be local, leveraging existing legitimate credentials within the affected WordPress environment.
OpenCVE Enrichment