What the vulnerability does
01Description
Missing Authorization vulnerability in WriterSystem WooCommerce Easy Duplicate Product.This issue affects WooCommerce Easy Duplicate Product: from n/a through 0.3.0.7.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in WriterSystem WooCommerce Easy Duplicate Product.This issue affects WooCommerce Easy Duplicate Product: from n/a through 0.3.0.7.
Explanation of Vulnerability in Simple Terms
WooCommerce Easy Duplicate Product versions up to 0.3.0.7 lack proper authorization checks on product duplication functions. A logged-in user with low privileges can duplicate products without the necessary permissions, potentially modifying the product catalog. The vulnerability requires an active WordPress user account but no special interaction.
What an attacker can do
Duplicate WooCommerce products without proper authorization.
Potential impact on your site
Unauthorized users can create duplicate products, potentially cluttering or manipulating your WooCommerce catalog.
Conditions required to exploit
Attacker must have a low-privilege WordPress user account (e.g., subscriber or contributor).
Key dates
External resources
Related vulnerabilities