Impact
The Hippoo Mobile App for WooCommerce plugin (versions up to 1.9.5) contains a flaw that allows attackers who are not authenticated to bypass access restrictions. This enables them to perform any action that a legitimate user is permitted to execute, potentially exposing sensitive information or altering site content. The weakness aligns with CWE-862, which denotes improper enforcement of access control.
Affected Systems
The vulnerability affects all WordPress sites that have the Hippoo Mobile App for WooCommerce plugin from hippooo installed at version 1.9.5 or earlier. Any user or process without valid credentials can exploit the broken control to gain elevated privileges.
Risk and Exploitability
The CVSS score of 8.2 places the bug in the high severity category. EPSS indicates a very low probability of exploitation (<1%). The vulnerability is not included in the CISA KEV catalog. Attackers can reach the flaw remotely through HTTP requests to the plugin’s endpoints, where authentication checks are missing, allowing complete bypass of access restrictions.
OpenCVE Enrichment