Impact
The vulnerability is an unauthenticated broken access control that allows anyone visiting a WordPress site with the Flexible Quantity – Measurement Price Calculator for WooCommerce plugin version 2.3.21 or earlier to manipulate quantity and measurement parameters. This grants of products and potentially inflate or deflate order totals, resulting in financial loss or unanticipated revenue changes.
Affected Systems
Any WordPress site running the wpdesk Flexible Quantity – Measurement Price Calculator for WooCommerce plugin version 2.3.21 or be installed, is the user’s authorization.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is <1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred as unauthenticated web requests to the plugin’s management endpoints; the attacker does not need authentication to exploit the flaw, so the risk is primarily to the site’s financial integrity.
OpenCVE Enrichment