Impact
The Stock Locations for WooCommerce plugin suffers from a missing authorization flaw that permits users to bypass the security controls originally placed on certain functions. This vulnerability arises from incorrectly configured access control security levels and enables exploitation of actions that should be confined to administrators, exposing sensitive inventory data and allowing manipulation of product stock information. Based on the description, it is inferred that the flaw results from incomplete authorization checks that allow users without proper privileges to execute functions.
Affected Systems
WordPress sites that have installed the Fahad Mahmood Stock Locations for WooCommerce plugin version 3.1.8 or earlier are impacted. The plugin is used to manage product inventory within WooCommerce shops, and any site using these versions inherits the flaw.
Risk and Exploitability
The flaw carries a medium CVSS score of 6.5, suggesting a moderate potential impact if used maliciously. The EPSS score is below 1%, indicating a low likelihood of widespread exploitation at this time, and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, because the flaw can be triggered through standard web requests to the plugin’s endpoints, any user able to reach the WordPress installation could potentially gain unauthorized privileges or data access. The likely attack vector is via standard web requests to the plugin’s endpoints, which can be performed by any authenticated or unauthenticated user with site access.
OpenCVE Enrichment