Impact
A missing authorization check in the Andy Ha DEPART WordPress plugin lets attackers perform, view, or modify deposit and part‑payment actions that should be restricted to privileged users. The weakness is categorized as CWE‑862, representing a missing privilege or authorization check.
Affected Systems
The issue affects the DEPART Deposit and Part Payment for Woo plugin by Andy Ha in all releases up to and including version 1.0.7. Any WordPress site that has this plugin installed and not yet upgraded is potentially exposed to attackers.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers would likely exploit the flaw by sending crafted HTTP requests to endpoints exposed by the plugin, though the advisory does not detail precise triggers. The impact remains limited to the functionality provided by the plugin and does not directly affect core WordPress components.
OpenCVE Enrichment