Impact
The vulnerability in the VillaTheme ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce plugin allows an attacker to bypass authentication checks, effectively masquerading as any authorized user. This flaw is classified as CWE‑1390, a broken authentication weakness, and can enable an attacker to access, modify, or delete WooCommerce orders, customer data, and other sensitive site information.
Affected Systems
All WordPress sites running the ALD plugin version 2.2.0 or earlier are affected. The plugin connects WooCommerce stores with AliExpress for dropshipping and fulfillment, so any installation of these or earlier versions will be susceptible.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate severity, while the EPSS score of < 1% implies a very low probability of exploitation and the vulnerability is not listed in CISA’s KEV catalog. The flaw permits unauthenticated requests to specific plugin endpoints, so an attacker does not require any prior credentials or special conditions. If the vulnerability is successfully leveraged, the attacker could gain the privileges of an authenticated user, potentially gaining full administrative control over the WooCommerce store.
OpenCVE Enrichment