Impact
The Partial Shipment for WooCommerce plugin permits authenticated users with the Subscriber role or higher to read and modify order details of any order. Because the AJAX handlers for wxp_order_shipment, wxp_order_item_shipment, and wxp_order_set_shipped lack capability checks and nonce verification, an attacker can trigger these actions to change shipped counts and to force order status transitions. This leads to unauthorized alterations in inventory and revenue tracking under the missing‑authorization weakness (CWE‑862).
Affected Systems
The flaw affects all installations of the wpexpertshub Partial Shipment for WooCommerce plugin version 3.4 and earlier on WordPress sites. Any site using this plugin with standard WordPress user roles conditional on the Subscriber level or above is vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity, while the EPSS score of less than 1 percent signals a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers need only authenticated access to the WordPress site and knowledge of the exposed AJAX endpoints; no privilege escalation or remote code execution is required.
OpenCVE Enrichment