What the vulnerability does
01Description
Missing Authorization vulnerability in Vark Pricing Deals for WooCommerce.This issue affects Pricing Deals for WooCommerce: from n/a through 2.0.3.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Vark Pricing Deals for WooCommerce.This issue affects Pricing Deals for WooCommerce: from n/a through 2.0.3.2.
Explanation of Vulnerability in Simple Terms
Pricing Deals for WooCommerce versions up to 2.0.3.2 lack proper authorization checks, allowing unauthenticated attackers to modify pricing data. The vulnerability requires only network access and no user interaction. Site owners should update to a version newer than 2.0.3.2 to prevent unauthorized price changes.
What an attacker can do
Modify product pricing and deal settings without authentication.
Potential impact on your site
Attackers can alter product prices and promotional deals, potentially causing revenue loss or customer confusion.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities