Impact
The Insecure Direct Object Reference that allows a user to manipulate identifiers in requests to the Product Slider for WooCommerce plugin, potentially exposing or tampering with product information. This weakness is classified as CWE‑639 and permits unauthorized reading or modification of resources that should be protected.
Affected Systems
The affected product is PickPlugins' Product Slider for WooCommerce. Versions up to and including 1.13.62 are at risk on any WordPress site that uses this plugin without updating beyond 1.13.62.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1% suggests a very low likelihood of exploitation at current time. The vulnerability is not listed in CISA's KEV catalog. The likely attack vector is inference from the IDOR nature of or form parameters to access protected data.
OpenCVE Enrichment