Impact
The vulnerability in the WC Vendors WordPress plugin prior to version 2.7.2.1 allows an authenticated vendor to change the shipment status of any order without verifying ownership of that order. This can result in the order being marked as shipped, an order note being added falsely attributed to the victim vendor, and the customer receiving a shipment notification email that was not actually sent by the vendor. The flaw represents a classic access control weakness in a multi‑tenant marketplace environment, effectively permitting one vendor to manipulate another vendor's transaction state and mislead end customers.
Affected Systems
Any WordPress site that installs the WC Vendors plugin with a version older than 2.7.2.1 is susceptible. Site administrators should identify installations of WC Vendors and confirm the current plugin version, ensuring it is updated to at least 2.7.2.1 or later.
Risk and Exploitability
Although no CVSS score is published and EPSS information is missing, the flaw is of high concern because it requires only that the attacker be an authenticated vendor, a role that is likely widely available on the platform. The attacker can tamper with orders from any vendor, potentially causing financial loss, reputational damage, and customer dissatisfaction. The vulnerability is not listed in CISA’s KEV catalog, but the impact and ease of exploitation warrant proactive remediation. There is no known public exploit, yet the verification step is trivial for a privileged user.
OpenCVE Enrichment