Description
Missing Authorization vulnerability in Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects License Manager for WooCommerce: from n/a through <= 3.0.17.
Published: 2026-07-13
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The License Manager for WooCommerce plugin suffers from a missing authorization flaw that allows attackers to delete any content managed by the plugin. Because the vulnerability stems from incorrectly configured access control, the attacker does not need privileged credentials; any user who can reach the plugin’s endpoints may trigger deletion. The impact is the loss of important product listings, coupons, or other managed data, which can disrupt e-commerce operations and damage customer trust.

Affected Systems

All versions of Saad Iqbal’s License Manager for WooCommerce up to and including 3.0.17 are affected. The plugin lacks the necessary capability checks in the code path responsible for content removal, exposing all installations within this version range to deletion risk.

Risk and Exploitability

The CVSS v3.1 score of 5.4 categorizes the issue as medium severity, while the EPSS score of less than 1 percent indicates a low probability of exploitation in the wild. The flaw is not listed in CISA’s KEV catalog, suggesting it has not yet been publicly exploited at scale. Based on the description, it is inferred that attackers would likely submit a crafted HTTP request to the plugin’s deletion endpoint, which the code processes without verifying the caller’s privileges. The likely attack vector is an unauthorized or low‑privilege user exploiting the deletion endpoint. The combination of a moderate severity score and low exploitation likelihood makes the risk moderate but warrants timely remediation.

Generated by OpenCVE AI on August 1, 2026 at 10:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the License Manager for WooCommerce plugin to a version newer than 3.0.17, if available; the official fix has been applied in later releases.
  • If an upgrade is not possible, remove the deletion capability from all non‑administrator roles by adjusting the plugin’s role settings or using a role editor plugin.
  • Restrict access to the WordPress administrative area and audit user roles to ensure that only trusted administrators retain deletion privileges.

Generated by OpenCVE AI on August 1, 2026 at 10:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Saad Iqbal License Manager for WooCommerce license-manager-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects License Manager for WooCommerce: from n/a through <= 3.0.17.
Title WordPress License Manager for WooCommerce plugin <= 3.0.17 - Arbitrary Content Deletion vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T14:12:13.745Z

Reserved: 2026-07-13T06:13:44.978Z

Link: CVE-2026-61958

cve-icon Vulnrichment

Updated: 2026-07-13T14:12:09.893Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:15:03Z

Weaknesses