Impact
The vulnerability is a broken access control flaw in the Shirt Product Designer for WooCommerce plugin version 1.0.4. It allows an unauthenticated attacker to bypass the plugin’s intended restriction on certain actions, enabling execution of privileged operations that should be limited to authenticated users with the appropriate role.
Affected Systems
WordPress sites that have installed the Shirt Product Designer for WooCommerce plugin version 1.0.4 from the mlfactory vendor are affected. The flaw is present only in that specific plugin version.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity vulnerability. The EPSS score is not available, so the exact probability of exploitation cannot be determined, but the lack of an authentication requirement means any visitor can attempt to exploit it. The vulnerability is not listed in CISA’s KEV catalog, indicating no publicly known exploitation at the time of this assessment. A potential attacker may target the plugin’s protected endpoints to gain unauthorized access to privileged actions.
OpenCVE Enrichment