What the vulnerability does
01Description
Missing Authorization vulnerability in NervyThemes SKU Label Changer For WooCommerce.This issue affects SKU Label Changer For WooCommerce: from n/a through 3.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in NervyThemes SKU Label Changer For WooCommerce.This issue affects SKU Label Changer For WooCommerce: from n/a through 3.0.
Explanation of Vulnerability in Simple Terms
The SKU Label Changer For WooCommerce plugin fails to properly check user permissions before allowing modifications to product SKU labels. An unauthenticated attacker can modify or delete SKU labels on any product without authorization. This affects all versions up to 3.0. Site owners should update to a version newer than 3.0 if available, or disable the plugin until a patch is released.
What an attacker can do
Modify or delete product SKU labels on your WooCommerce store without any authentication.
Potential impact on your site
Product SKU data can be corrupted or deleted by anyone, disrupting inventory management and order fulfillment.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities