Impact
This vulnerability is a missing authorization flaw that allows an attacker to interact with the pickup point configuration in the Viszt Péter Csomagpontok és szállítási címkék WooCommerce-hez plugin without the required privileges. Correctly configured access controls are bypassed, enabling unauthorized users to create, modify or delete pickup points, potentially impacting the order fulfillment workflow and exposing sensitive shipping data. The weakness is a classic broken access control, listed as CWE-862.
Affected Systems
The affected product is the WordPress plugin Viszt Péter Csomagpontok és szállítási címkék WooCommerce-hez. Versions prior to 4.2.8 are affected, with no patched release available in the current version set. The vulnerability exists throughout the plugin’s API endpoints that manage pickup point data.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity with significant impact on confidentiality, integrity and availability. The EPSS score is not provided, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Based on the description, the likely attack vector is through the WordPress web interface, where a non‑administrator user could exploit the exposed endpoints. Exploitation requires authentication to the WordPress site; an attacker with any logged‑in role could leverage the broken controls to affect pickup point configuration.
OpenCVE Enrichment