Impact
The JTL-Connector for WooCommerce plugin for WordPress suffers from missing capability checks and nonce verification on the admin_post_settings_save_woo-jtl-connector action and on the wp_ajax_downloadJTLLogs and wp_ajax_clearJTLLogs AJAX actions. Authenticated users with the Subscriber role or higher can therefore modify arbitrary plugin settings, download a ZIP archive of the connector’s developer log files, and delete those log files. These actions enable unauthorized configuration changes and the potential exposure of sensitive developer logs, constituting a privilege escalation and confidentiality breach.
Affected Systems
The affected product is the ntbyk JTL-Connector for WooCommerce WordPress plugin. All releases up to and including version 2.4.1 are vulnerable.
Risk and Exploitability
The CVSS base score is 4.3, indicating a moderate severity. The EPSS score is not available, so the likelihood of exploitation is unknown, but because the attack requires only an authenticated Subscriber account, the opportunity is realistic for any site with such users. The vulnerability is not listed in the CISA KEV catalogue at this time. Patching the plugin or otherwise restricting access to the affected actions mitigates the risk.
OpenCVE Enrichment