Impact
The WC Vendors WordPress plugin version 2.7.2.1 and earlier fails to verify the ownership or object type of user-supplied IDs when saving product variations. As a result, an authenticated user with the vendor role can change product variations belonging to other vendors and update the status and title of any post, giving the attacker full control over unrelated data.
Affected Systems
WordPress sites that use the WC Vendors plugin of any vendor, but only when the installed version is older than 2.7.2.1. The vulnerability is specific to the plugin's product variation management and post handling modules.
Risk and Exploitability
The flaw constitutes an IDOR and carries high integrity risk. While the EPSS score is not provided, the lack of ownership checks suggests low technical barriers for exploitation. Attackers require only a vendor role and the knowledge of target IDs, which can often be enumerated from the site. The vulnerability is not listed in KEV, but its potential for data tampering makes it a high‑severity issue for any affected environment.
OpenCVE Enrichment