What the vulnerability does
01Description
Missing Authorization vulnerability in WebCodingPlace Product Expiry for WooCommerce.This issue affects Product Expiry for WooCommerce: from n/a through 2.5.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in WebCodingPlace Product Expiry for WooCommerce.This issue affects Product Expiry for WooCommerce: from n/a through 2.5.
Explanation of Vulnerability in Simple Terms
Product Expiry for WooCommerce versions up to 2.5 lack proper authorization checks, allowing authenticated users to modify or disable product expiry settings they should not have access to. An attacker with low-level site access can alter product expiration dates or availability rules, affecting site integrity. Update to a version newer than 2.5.
What an attacker can do
Modify or disable product expiry settings without proper authorization.
Potential impact on your site
Unauthorized users can alter product expiration rules, potentially disrupting inventory management and sales logic.
Conditions required to exploit
Attacker must have a low-privilege authenticated account on the site.
Key dates
External resources
Related vulnerabilities