What the vulnerability does
01Description
Missing Authorization vulnerability in Woo WooCommerce Warranty Requests.This issue affects WooCommerce Warranty Requests: from n/a through 2.1.9.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
What the vulnerability does
Missing Authorization vulnerability in Woo WooCommerce Warranty Requests.This issue affects WooCommerce Warranty Requests: from n/a through 2.1.9.
Explanation of Vulnerability in Simple Terms
WooCommerce Warranty Requests fails to properly check user permissions before allowing access to warranty request data. A logged-in user with low privileges can read and modify warranty requests belonging to other customers or store administrators. The vulnerability affects versions up to 2.1.9 and requires only a valid user account to exploit.
What an attacker can do
Read and modify warranty requests belonging to other customers or administrators.
Potential impact on your site
Customer warranty data and admin warranty records are exposed to unauthorized access and modification by any logged-in user.
Conditions required to exploit
Attacker must have a valid user account on the site (low privilege level sufficient).
Key dates
External resources
Related vulnerabilities