Impact
The vulnerability is a missing authorization check on the plugin's REST API endpoints, allowing any visitor to modify Social Commerce for WooCommerce configuration settings and mark products as synchronized or not. This can alter how products appear on the front‑end, disable protective features, or trigger fraudulent sales actions. The weakness is a classic example of missing authorization control, as identified by CWE‑862.
Affected Systems
Social Commerce for WooCommerce, versions 2.5.4 and earlier, deployed on WordPress sites are impacted. No other vendors or product variants are listed.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk; the EPSS score is not available and the vulnerability is not currently listed in the CISA KEV catalog. The attack vector is purely web‑based: an unauthenticated user can access the vulnerable REST endpoints over HTTP or HTTPS by knowing or guessing the URL. No additional privileges or network access are required to exploit this flaw.
OpenCVE Enrichment