Impact
Missing authorization checks in the SureCart WordPress plugin let attackers bypass built‑in access controls and access protected order, payment, and client data, thereby compromising confidentiality, integrity, and availability. The weakness is a missing access control (CWE‑862).
Affected Systems
Any WordPress site running SureCart version 4.0.2 or older is affected. Sites using these versions expose reverse‑engineered or public endpoints that can be accessed without proper authentication, allowing attackers to view or modify e‑commerce data.
Risk and Exploitability
The CVSS base score of 6.5 indicates medium severity, while the EPSS score of less than 1 % suggests a low chance of real‑world exploitation. The vulnerability is not in the CISA KEV catalog. Attackers can exploit the flaw by sending unauthenticated or minimally authenticated HTTP requests to privileged plugin routes; the attack vector is inferred from the description rather than explicitly declared.
OpenCVE Enrichment