Impact
The IDOR flaw in the VillaTheme COMPE WordPress plugin allows an attacker to manipulate a user-controlled key used to locate resources such as comparison lists. Based on the description, the likely attack vector is constructing HTTP requests that supply the key; the plugin does not properly verify ownership, letting a user retrieve or modify objects they are not entitled to access, thereby compromising confidentiality and integrity of that data.
Affected Systems
The vulnerability applies to the VillaTheme COMPE compe-woo-compare-products plugin for WordPress, versions up through and including 1.1.4. Custom installations of this plugin that have not upgraded past these versions are susceptible.
Risk and Exploitability
The vulnerability permits direct unauthorized access to protected objects via predictable URLs or query parameters. Based on the description, the likely attack vector is an attacker guessing or enumerating the key across the network by sending crafted requests. The CVSS score of 5.3 indicates a moderate severity, while the EPSS score of less than 1% and absence from CISA KEV suggest low to moderate exploitation likelihood. An attacker who successfully guesses or enumerates the key can retrieve or modify another user's comparison lists over the network, potentially compromising confidentiality and integrity and providing a foothold for further site compromise.
OpenCVE Enrichment