Description
Missing Authorization vulnerability in Fahad Mahmood Stock Locations for WooCommerce stock-locations-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stock Locations for WooCommerce: from n/a through <= 3.1.8.
Published: 2026-07-13
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Stock Locations for WooCommerce plugin suffers from a missing authorization flaw that permits users to bypass the security controls originally placed on certain functions. This vulnerability arises from incorrectly configured access control security levels and enables exploitation of actions that should be confined to administrators, exposing sensitive inventory data and allowing manipulation of product stock information. Based on the description, it is inferred that the flaw results from incomplete authorization checks that allow users without proper privileges to execute functions.

Affected Systems

WordPress sites that have installed the Fahad Mahmood Stock Locations for WooCommerce plugin version 3.1.8 or earlier are impacted. The plugin is used to manage product inventory within WooCommerce shops, and any site using these versions inherits the flaw.

Risk and Exploitability

The flaw carries a medium CVSS score of 6.5, suggesting a moderate potential impact if used maliciously. The EPSS score is below 1%, indicating a low likelihood of widespread exploitation at this time, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, because the flaw can be triggered through standard web requests to the plugin’s endpoints, any user able to reach the WordPress installation could potentially gain unauthorized privileges or data access. The likely attack vector is via standard web requests to the plugin’s endpoints, which can be performed by any authenticated or unauthenticated user with site access.

Generated by OpenCVE AI on July 31, 2026 at 11:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available vendor patch or upgrade to a plugin version newer than 3.1.8.
  • If an upgrade is not immediately possible, disable or uninstall the plugin to prevent access to the vulnerable endpoints.
  • Ensure only trusted administrator accounts have sufficient privileges to prevent misuse of any related features that remain available through other plugins or custom code.

Generated by OpenCVE AI on July 31, 2026 at 11:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Fahadmahmood8
Fahadmahmood8 stock Locations For Woocommerce
Wordpress
Wordpress wordpress
Vendors & Products Fahadmahmood8
Fahadmahmood8 stock Locations For Woocommerce
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Fahad Mahmood Stock Locations for WooCommerce stock-locations-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stock Locations for WooCommerce: from n/a through <= 3.1.8.
Title WordPress Stock Locations for WooCommerce plugin <= 3.1.8 - Broken Access Control vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Fahadmahmood8 Stock Locations For Woocommerce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T13:50:37.405Z

Reserved: 2026-06-24T12:46:38.624Z

Link: CVE-2026-57419

cve-icon Vulnrichment

Updated: 2026-07-13T13:50:34.137Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:00:05Z

Weaknesses