Impact
An unauthenticated Insecure Direct Object Reference vulnerability exists in versions 5.1.0 and earlier of the Vendidero Shiptastic for WooCommerce plugin. If exploited, attacker can request resources belonging to other users by manipulating identifiers in URLs or requests, enabling unauthorized reading or modification of protected data. The weakness corresponds to CWE-639, indicating that the application fails to restrict access to objects without proper validation.
Affected Systems
The vulnerability affects the WordPress Shiptastic for WooCommerce plugin by Vendidero, specifically all installations running version 5.1.0 or earlier. Users running these versions on any WordPress site are potentially exposed to unauthorized data access.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium impact, and the EPSS score of less than 1 % suggests a low likelihood of widespread exploitation as of the latest assessment. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to discover or guess valid object identifiers and issue HTTP requests; no authentication is required, so the attack surface is wide across any publicly reachable site hosting the affected plugin.
OpenCVE Enrichment