What the vulnerability does
01Description
Improper Authentication vulnerability in Pluggabl LLC Booster Elite for WooCommerce allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Booster Elite for WooCommerce: from n/a before 7.1.3.
Explanation of Vulnerability in Simple Terms
02Summary
Booster Elite for WooCommerce versions before 7.1.3 contain an authentication flaw that allows logged-in users with low privileges to modify data they should not have access to. The vulnerability does not expose sensitive information or crash the site, but it does permit unauthorized changes to site content or settings. Update to version 7.1.3 or later to resolve this issue.
What an attacker can do
03Attacker Capabilities
A logged-in user can modify data or settings they should not have permission to change.
Potential impact on your site
04Site Impact
Unauthorized users may alter WooCommerce settings, product data, or other protected content without admin approval.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege account on the site (e.g., subscriber or contributor role).
Key dates
06Disclosure timeline
June 4, 2024
CVE published
April 28, 2026
Record updated