Impact
The vulnerability is a missing authorization flaw that allows attackers to access administrative functions of the EDGARROJAS Extra Product Options Builder for WooCommerce plugin without proper permission. This could enable unauthorized manipulation of product option settings and compromise the integrity of a WooCommerce store. The weakness is classified as CWE‑862 (Missing Authorization).
Affected Systems
The vulnerability affects sites that have the EDGARROJAS Extra Product Options Builder for WooCommerce plugin version 1.2.167 or earlier. No other vendors or products are reported as affected by this CVE.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity. The EPSS of <1% suggests a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that to the plugin’s administrative endpoints, potentially from any user with network access to the WordPress installation, to bypass standard authorization checks.
OpenCVE Enrichment