Description
Unauthenticated Broken Access Control in Morning for WooCommerce <= 2.4.1 versions.
Published: 2026-10-06
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Unauthorized privileged access
Action: Immediate Update
AI Analysis

Impact

This vulnerability is an unauthenticated broken access control flaw affecting the Morning for WooCommerce plugin. An attacker who can trigger the vulnerable code can bypass normal authorization checks and gain unauthorized access to privileged functions or data, potentially allowing modification or exposure of sensitive information. The weakness corresponds to CWE-862, which involves improper authorization checks.

Affected Systems

The affected systems are WordPress sites that have installed the Green Invoice Morning for WooCommerce plugin at versions up to and including 2.4.1. No patch version is listed in the data, but the issue is specific to all releases 2.4.1 or earlier.

Risk and Exploitability

The CVSS score for this flaw is 7.5, indicating a high risk to confidentiality and integrity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw can be exploited with no authentication, the likely attack vector is a web‑based request to a vulnerable endpoint or admin interface, allowing an attacker to send crafted requests from any IP.

Generated by OpenCVE AI on October 6, 2026 at 06:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Green Invoice Morning for WooCommerce plugin to the latest version available (any release newer than 2.4.1) to eliminate the broken access control flaw.
  • If an update is not immediately available, temporarily disable or remove the plugin until a patched version is released, ensuring that no privileged functions remain exposed.
  • Review and tighten user role permissions on the WordPress site, ensuring that only authorized administrators have access to the plugin’s privileged configuration pages; implement additional logging or monitoring for unexpected access attempts.

Generated by OpenCVE AI on October 6, 2026 at 06:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 05:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Access Control in Morning for WooCommerce <= 2.4.1 versions.
Title WordPress Morning for WooCommerce plugin <= 2.4.1 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-06T05:14:48.278Z

Reserved: 2026-04-07T10:58:34.148Z

Link: CVE-2026-39723

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T06:17:00.947

Modified: 2026-10-06T06:17:00.947

Link: CVE-2026-39723

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T07:00:14Z

Weaknesses