What the vulnerability does
01Description
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Square.This issue affects WooCommerce Square: from n/a through 3.8.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
What the vulnerability does
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Square.This issue affects WooCommerce Square: from n/a through 3.8.1.
Explanation of Vulnerability in Simple Terms
WooCommerce Square versions up to 3.8.1 contain an authorization flaw that allows authenticated users with low privileges to read sensitive payment and order data, and disrupt service availability. The vulnerability stems from insufficient access controls on administrative functions. Attackers need a valid user account but no special permissions to exploit it.
What an attacker can do
Read sensitive payment data and order information; disrupt service availability.
Potential impact on your site
Customer payment records and order details may be exposed to any logged-in user; site availability may be compromised.
Conditions required to exploit
Valid WooCommerce user account with low or standard privileges; network access to the site.
Key dates
External resources
Related vulnerabilities