What the vulnerability does
01Description
Missing Authorization vulnerability in WPXPO WowStore product-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WowStore: from n/a through <= 2.7.8.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in WPXPO WowStore product-blocks allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WowStore: from n/a through <= 2.7.8.
Explanation of Vulnerability in Simple Terms
WowStore versions up to 2.7.8 lack proper authorization checks, allowing an attacker to modify data on the site if a user visits a malicious link. The vulnerability requires user interaction and does not affect data confidentiality or availability. Site administrators should update to a version newer than 2.7.8.
What an attacker can do
Modify site data if a user clicks a malicious link.
Potential impact on your site
Unauthorized changes to site content or settings if users are tricked into clicking malicious links.
Conditions required to exploit
No authentication required; victim must click attacker-supplied link.
Key dates
External resources
Related vulnerabilities