Impact
The Blacklist Manager for WooCommerce plugin fails to enforce user blocks on all authentication routes, allowing a blocked account to authenticate and use the site owner's permissions. This flaw permits an attacker who controls a blocked user account to continue accessing the system with that account’s authority, effectively bypassing the intended restriction.
Affected Systems
The vulnerability affects the Blacklist Manager for WooCommerce plugin for WordPress, specifically versions 1.3.0 through 2.3.1. This plugin is used to block users on WooCommerce‑powered WordPress sites.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity; the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is likely through authentication paths that rely on XML‑RPC or application passwords, as suggested by the title. An attacker who owns a blocked user account can exploit this bypass to gain unauthorized access with the blocked account’s privileges. The exploit requires only that the attacker controls a blocked account and can use the site’s authentication mechanisms.
OpenCVE Enrichment