Impact
Unauthenticated Broken Access Control exists in Syncee Premium Dropshipping & Wholesale plugin through version 1.0.27. The vulnerability allows an attacker without valid credentials to access privileged administrative functions within the plugin. The flaw is identified as CWE‑862. An attacker could potentially alter shipping or wholesale settings, manipulate product listings, or otherwise tamper with the store’s configuration.
Affected Systems
The affected product is Akosglys’ Syncee Premium Dropshipping & Wholesale plugin, versions 1.0.27 and earlier. It is a WordPress plugin used on e‑commerce sites; any WordPress installation that has this plugin installed at the vulnerable version is at risk.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. EPSS is not available, but the lack of a KEV listing and the nature of the flaw suggest a medium to high likelihood of exploitation. An unauthenticated user can send crafted HTTP requests to the plugin’s administration URLs, gaining full control over the plugin’s settings. This could enable the attacker to modify shipping rates, wholesale prices, or inject fraudulent product data, thereby impacting the store’s integrity and potentially financial loss.
OpenCVE Enrichment