Impact
A missing authorization check in the g5theme Book Previewer for Woocommerce plugin enables attackers to access protected content that should be restricted. The flaw arises from an incorrectly configured access control level, allowing an unauthenticated user to retrieve preview files or sensitive product data. The impact is the potential unauthorized disclosure of proprietary or customer information, potentially compromising confidentiality.
Affected Systems
The vulnerability affects the g5theme Book Previewer for Woocommerce plugin for WordPress, versions from the earliest release through version 1.0.6. WordPress sites that host books or other copyrighted material and rely on this plugin as a preview mechanism are vulnerable.
Risk and Exploitability
While the CVSS score is not provided, the nature of broken access control typically results in high severity. No EPSS value is available, but an attacker can exploit the flaw simply by crafting a request to the preview endpoint, which is publicly reachable on a WordPress installation. The flaw is not listed in KEV, indicating no known large-scale exploitation yet, but the ease of access poses a significant risk to all affected sites.
OpenCVE Enrichment