Impact
The vulnerability is an unauthenticated bypass in the WordPress Pre‑Orders for WooCommerce plugin, version 2.3 and earlier. By exploiting the flaw an attacker can subvert access controls to interact with pre‑order functionality without legitimate authentication. This can enable the creation, modification, or cancellation of pre‑orders, potentially altering order data and undermining the integrity of the WooCommerce store.
Affected Systems
Affected products include BrightVesselDev's Pre‑Orders for WooCommerce plugin for WordPress, versions 2.3 and below. Any WordPress installation running these versions of the plugin is susceptible.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog. The flaw is likely exploitable through web requests, allowing unauthenticated users to craft inputs that bypass normal authorization checks. Once accessed, an attacker can perform privileged actions within the plugin, though the scope is confined to the plugin's exposed functionality.
OpenCVE Enrichment