What the vulnerability does
01Description
Missing Authorization vulnerability in Putler / Storeapps Putler Connector for WooCommerce.This issue affects Putler Connector for WooCommerce: from n/a through 2.12.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Putler / Storeapps Putler Connector for WooCommerce.This issue affects Putler Connector for WooCommerce: from n/a through 2.12.0.
Explanation of Vulnerability in Simple Terms
The Putler Connector for WooCommerce plugin does not properly check user permissions before allowing access to sensitive functions. An attacker without authentication can read and modify certain data on the site. This affects versions up to 2.12.0. Site owners should update to a version newer than 2.12.0 as soon as possible.
What an attacker can do
Read and modify sensitive site data without logging in.
Potential impact on your site
Unauthorized users can access and alter WooCommerce data and settings without a valid account.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities