Impact
The vulnerability exists in the Product Badge, Label, Countdown Timer for WooCommerce WordPress plugin prior to version 7.5.2 because it does not enforce a check on product publication status before returning product details. As a result, any visitor, without authentication, can access the title, description and price of draft, pending and private products, exposing confidential business information and potentially revealing pricing strategies and inventory status.
Affected Systems
All WordPress sites using the Product Badge, Label, Countdown Timer for WooCommerce plugin in the 7.0.0 through 7.5.1 range are impacted. The issue affects only the plugin and not the WordPress core or WooCommerce itself. The affected versions are all those released before 7.5.2.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. The EPSS score of less than 1% suggests that the likelihood of exploitation is currently low, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires only an unauthenticated HTTP request to the plugin’s product detail endpoints, meaning that an attacker only needs to know or guess a product identifier. No additional credentials or elevated privileges are required.
OpenCVE Enrichment