What the vulnerability does
01Description
Missing Authorization vulnerability in printful Printful Integration for WooCommerce printful-shipping-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Printful Integration for WooCommerce: from n/a through <= 2.2.3.
Explanation of Vulnerability in Simple Terms
02Summary
The Printful Integration for WooCommerce plugin does not properly check user permissions before allowing access to certain functions. A logged-in user with low privileges can read sensitive information they should not have access to. The vulnerability affects versions up to 2.2.3. Site owners should update to a version newer than 2.2.3.
What an attacker can do
03Attacker Capabilities
Read sensitive information from the plugin that should be restricted to higher-privilege users.
Potential impact on your site
04Site Impact
Customer or subscriber accounts can access restricted plugin data, potentially exposing business or order information.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege account on the WooCommerce site (e.g., customer or subscriber role).
Key dates
06Disclosure timeline
December 13, 2024
CVE published
April 29, 2026
Record updated