What the vulnerability does
01Description
Missing Authorization vulnerability in Zorem Sales Report Email for WooCommerce.This issue affects Sales Report Email for WooCommerce: from n/a through 2.8.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in Zorem Sales Report Email for WooCommerce.This issue affects Sales Report Email for WooCommerce: from n/a through 2.8.
Explanation of Vulnerability in Simple Terms
The Sales Report Email for WooCommerce plugin through version 2.8 does not properly restrict access to sensitive report data. A logged-in user with low privileges can view sales reports they should not have access to. This allows unauthorized disclosure of business metrics and sales information that should be limited to administrators or managers.
What an attacker can do
View sales reports and business data they are not authorized to access.
Potential impact on your site
Confidential sales data and business metrics may be exposed to unauthorized users with site accounts.
Conditions required to exploit
Attacker must have a low-privilege account on the WooCommerce site (e.g., customer or subscriber role).
Key dates
External resources
Related vulnerabilities