Impact
This vulnerability arises from an allocation of resources without limits or throttling in the WooCommerce plugin. Crafting HTTP requests that exhaust server memory or CPU can lead to service disruption, resulting in a denial of service that can affect the availability of the affected e‑commerce site. Based on the description, it is inferred that attackers would likely use repeated HTTP requests to trigger this resource exhaustion.
Affected Systems
The flaw is present in all versions of the WooCommerce plugin distributed by Automattic that are older than 11.1.0. Any WordPress site using these outdated plugin releases is susceptible, regardless of the underlying WordPress version or hosting environment.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, and the vulnerability is rated as a denial of service. The EPSS score is not available, so the current exploitation probability cannot be quantified, but the problem remains unpatched in many systems. Based on the description, it is inferred that attackers would likely exploit it through repeated HTTP requests, hoping to exhaust server resources. The vulnerability is not listed in CISA KEV. Early patching or mitigation is therefore recommended.
OpenCVE Enrichment