What the vulnerability does
01Description
Missing Authorization vulnerability in VillaTheme(villatheme.com) ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce: from n/a through 1.0.21.
Explanation of Vulnerability in Simple Terms
02Summary
The ALD plugin for WooCommerce fails to properly check user permissions before allowing access to certain administrative functions. A logged-in user with low privileges can view sensitive information they should not have access to. The vulnerability affects versions up to 1.0.21. Update to a version newer than 1.0.21 to resolve this issue.
What an attacker can do
03Attacker Capabilities
View sensitive information restricted to higher-privilege users.
Potential impact on your site
04Site Impact
Unauthorized users can access confidential data like order details or plugin settings.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege account on the WooCommerce site.
Key dates
06Disclosure timeline
December 13, 2024
CVE published
April 28, 2026
Record updated