Impact
This vulnerability is an unauthenticated broken access control flaw affecting the Morning for WooCommerce plugin. An attacker who can trigger the vulnerable code can bypass normal authorization checks and gain unauthorized access to privileged functions or data, potentially allowing modification or exposure of sensitive information. The weakness corresponds to CWE-862, which involves improper authorization checks.
Affected Systems
The affected systems are WordPress sites that have installed the Green Invoice Morning for WooCommerce plugin at versions up to and including 2.4.1. No patch version is listed in the data, but the issue is specific to all releases 2.4.1 or earlier.
Risk and Exploitability
The CVSS score for this flaw is 7.5, indicating a high risk to confidentiality and integrity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw can be exploited with no authentication, the likely attack vector is a web‑based request to a vulnerable endpoint or admin interface, allowing an attacker to send crafted requests from any IP.
OpenCVE Enrichment