Impact
The Ni WooCommerce Sales Report WordPress plugin versions earlier than 4.2.0 lack both authentication and authorization checks on a report‑printing routine that accepts a 'btn_print' parameter. An attacker can invoke this routine without logging in, prompting the plugin to return detailed WooCommerce order data, including billing and shipping addresses, as well as customer contact information. The disclosed data may contain personal identifiers, financial details, and order history, which can be leveraged for identity theft, fraud, or further compromise.
Affected Systems
Any WordPress site that has the Ni WooCommerce Sales Report plugin installed with a version older than 4.2.0 is affected. The vulnerability is specific to the WordPress plugin and does not involve other components or operating systems beyond the WordPress installation that hosts the plugin.
Risk and Exploitability
The vulnerability is accessed via a standard HTTP request to the plugin’s print endpoint, which is reachable from the public web. The CVSS score of 5.3 classifies it as medium severity, and the EPSS score of less than 1% indicates a very low but non‑zero likelihood of exploitation. It is currently not listed in CISA’s KEV catalog, suggesting no widespread exploitation has been reported. Despite the low exploit probability, the sensitive nature of the exposed data warrants prompt mitigation.
OpenCVE Enrichment