Impact
The Empik for Woocommerce plug‑in fails to verify a user’s privileges before executing the empik_csv_process_emp_log_classes AJAX handler. An authenticated user who has a subscriber role or higher can exploit this gap to update any product’s metadata, including logistic class, product state, and export flags, effectively allowing the attacker to alter product behavior, availability, or shipping parameters. This represents a CWE‑862 improper authorization flaw where access control is insufficient.
Affected Systems
All installations of the Empik for Woocommerce plug‑in on WordPress from its initial release through version 1.5.1 are affected. The plug‑in can be found as empik:Empik for Woocommerce and is used by e‑commerce sites that rely on WooCommerce integration.
Risk and Exploitability
The vulnerability carries a CVSS score of 4.3, indicating a medium severity. Its EPSS score is below 1%, suggesting that active exploitation is currently rare. The plug‑in is not listed in the CISA KEV catalog, so no widespread exploitation is reported. Attackers need only be logged in with at least a subscriber role and to trigger the vulnerable AJAX action; no additional capabilities or user‑role escalation are required. While the chance of exploitation is low, the damage to product data integrity can be significant for affected stores.
OpenCVE Enrichment