Impact
The WC Fields Factory WordPress plugin versions prior to 4.1.11 suffers from an access‑control weakness that allows any authenticated user with Subscriber role or higher to call a vulnerable AJAX action. This action permits creation, modification, and deletion of arbitrary post meta on any post, including WooCommerce products. An attacker could thereby alter product attributes, modify stored pricing rules, or otherwise compromise the integrity and financial aspects of the site. The weakness is identified as CWE‑862, representing a missing authorization check.
Affected Systems
Any WordPress installation that hosts the WC Fields Factory plugin with a version older than 4.1.11 is affected. Sites using WooCommerce or similar systems that rely on custom post meta are particularly at risk, regardless of additional security settings.
Risk and Exploitability
The CVSS base score of 8.1 indicates a severe impact, while an EPSS score under 1% suggests that widespread exploitation has not yet been observed. Although the vulnerability is not yet listed in the CISA KEV catalogue, the straightforward attack path available to a legitimate Subscriber user raises the potential for targeted, low‑profile attacks. Immediate patching is advised to eliminate the risk of arbitrary post meta tampering and product price manipulation.
OpenCVE Enrichment