What the vulnerability does
01Description
Missing Authorization vulnerability in Woo WooCommerce Warranty Requests.This issue affects WooCommerce Warranty Requests: from n/a through 2.2.7.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in Woo WooCommerce Warranty Requests.This issue affects WooCommerce Warranty Requests: from n/a through 2.2.7.
Explanation of Vulnerability in Simple Terms
WooCommerce Warranty Requests versions up to 2.2.7 lack proper authorization checks, allowing unauthenticated attackers to modify warranty request data over the network. An attacker can alter or delete warranty records without needing to log in or interact with a user. Site owners should update immediately to prevent data tampering and service disruption.
What an attacker can do
Modify or delete warranty request records without authentication.
Potential impact on your site
Warranty data can be altered or deleted by anyone, disrupting customer service and trust.
Conditions required to exploit
Network access only; no login or user interaction required.
Key dates
External resources
Related vulnerabilities