Impact
The Botiga Pro plugin before version 1.6.5 exposes a REST route that does not perform authorisation checks. An unauthenticated attacker can use this route to update any WordPress option with arbitrary values, store malicious scripts that execute on every front‑end page, or move posts to the trash, effectively granting arbitrary configuration changes and persistent code execution. This weakness reflects a lack of access control (CWE‑862).
Affected Systems
Any WordPress site that has Botiga Pro installed at a version earlier than 1.6.5 is affected; no other vendor or product information is available.
Risk and Exploitability
Because the REST endpoint is publicly accessible and requires no authentication, it can theoretically be reached from any IP address that can access the site. This inference is based on the REST API nature of the route, which is not explicitly stated in the description. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the combination of a critical CVSS score of 9.8, an unauthenticated entry point, and the ability to modify global WordPress options makes the risk high and the potential impact essentially a full site takeover.
OpenCVE Enrichment