Impact
The vulnerability resides in the Order Delivery Date for WooCommerce plugin for WordPress and permits a user with a shop manager role to elevate privileges within the WordPress site. This escalated access allows the attacker to gain the full capabilities of an administrator, compromising confidentiality, integrity, and availability of site content and settings.
Affected Systems
All installations of the Order Delivery Date for WooCommerce plugin at or below version 4.6.0 are affected. The plugin is provided by Tyche Softwares under the vendor name 'tychesoftwares:Order Delivery Date for WooCommerce.'
Risk and Exploitability
The CVSS score for this flaw is 7.2, indicating a high severity risk. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed public exploits yet. The most probable attack vector is local: a user with shop manager permissions can exploit the flaw directly through the plugin interface or by submitting crafted requests to the site. Once exploited, the attacker can restructure user roles and compromise site management functions.
OpenCVE Enrichment