Impact
The SKU Error Fixer for WooCommerce plugin prior to version 1.0 contains missing capability and nonce checks on two AJAX actions that can be invoked by anyone without authentication. These actions allow a remote attacker to permanently delete product variations that the plugin marks as obsolete and to retrieve detailed information about those variations, resulting in data loss and potential disclosure of product data. The vulnerability is a direct result of improper access control and a lack of protection mechanisms.
Affected Systems
All installations of the plugin identified as SKU Error Fixer for WooCommerce with a version of 1.0 or earlier are affected. Since the plugin is an unknown vendor product, any WordPress site that has installed this plugin in the specified versions is at risk. No product version information beyond 1.0 was provided, so any version equal to or older than 1.0 remains vulnerable.
Risk and Exploitability
The vulnerability is exploitable through unauthenticated HTTP requests to the plugin’s AJAX endpoints. No friction or discovery barrier is mentioned, suggesting that the attack can be performed by anyone able to send requests to the site. No EPSS score is available, and the vulnerability is not listed in CISA KEV, but the impact on data integrity and confidentiality implies a moderate to high severity. Without an available patch, the risk remains present until the plugin is updated or the endpoint is protected.
OpenCVE Enrichment