What the vulnerability does
01Description
Missing Authorization vulnerability in Woo WooCommerce Canada Post Shipping.This issue affects WooCommerce Canada Post Shipping: from n/a through 2.8.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Woo WooCommerce Canada Post Shipping.This issue affects WooCommerce Canada Post Shipping: from n/a through 2.8.3.
Explanation of Vulnerability in Simple Terms
The WooCommerce Canada Post Shipping plugin through version 2.8.3 lacks proper authorization checks on certain functions. An unauthenticated attacker can modify shipping data or settings without permission. This affects the integrity of order information and shipping configurations on affected WooCommerce stores.
What an attacker can do
Modify shipping settings or data without authentication.
Potential impact on your site
Attackers can alter shipping rates, addresses, or carrier settings, disrupting order fulfillment.
Conditions required to exploit
Network access to the WooCommerce site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities