Impact
The vulnerability exists in MgoSync WordPress plugin versions before 2.1.7. A REST API endpoint lacks authorization checks, enabling any user to retrieve the stored WooCommerce API consumer key and secret associated with the site. The exposed credentials provide read/write access to the WooCommerce API, allowing the attacker to perform any action that the API permits.
Affected Systems
Any WordPress site that has the MgoSync plugin installed with a version earlier than 2.1.7 is affected. The "/mgosync/api/credentials" endpoint is the specific target. The presence of WooCommerce is required because the credentials are tied to that plugin, but the vulnerability does not depend on theme or other plugins.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, while an EPSS score of <1% suggests a low likelihood of exploitation noted at the time of analysis. The vulnerability is not listed in the CISA KEV catalog. Because the endpoint is reachable without authentication, exploitation requires only a simple HTTP request. Once an attacker obtains the consumer key and secret, the credentials grant full read/write permission to the store’s WooCommerce API, impacting confidentiality and integrity of store data.
OpenCVE Enrichment