Impact
The vulnerability allows unauthenticated users to read or download files attached to WooCommerce products, potentially leaking confidential or proprietary information. It is an example of a data exposure weakness (CWE‑497) where the plugin fails to enforce proper access restrictions on attachments.
Affected Systems
The affected product is the WooCommerce Product Attachment plugin, 2.3.3 or earlier, distributed by Dotstore. It is used in WordPress installations that host WooCommerce stores. No specific operating system or additional environment dependencies are cited.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. No EPSS score is provided, but the vulnerability is classified as unauthenticated, which means an attacker can exploit it without needing to authenticate to the site. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been observed in the wild, though the risk of data leakage remains significant. An attacker could craft a URL or use automated queries to enumerate and download attachments that should be protected.
OpenCVE Enrichment