Impact
WordPress WooCommerce POS plugin versions 1.8.14 and earlier suffer from an unauthenticated broken access control flaw that allows an attacker to perform privileged actions normally restricted to authenticated users. The vulnerability can enable an attacker to read, modify, or delete store data and potentially interfere with financial transactions. The weakness is classified as CWE‑862 and carries a CVSS score of 7.5, indicating high severity.
Affected Systems
All installations of the kilbot WooCommerce POS plugin running version 1.8.14 or lower are vulnerable. Sites that have not applied the upgrade to 1.9.0 or later run the risk if the plugin is enabled and web access to its administrative interfaces is not properly restricted.
Risk and Exploitability
The CVSS score of 7.5 marks this issue as high risk, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present, and it is not listed in CISA’s KEV catalog. The attack vector is inferred to be a web‑based request to the plugin’s endpoints, exploiting its lack of authentication checks, which could grant an attacker administrative privileges without credentials.
OpenCVE Enrichment