What the vulnerability does
01Description
Missing Authorization vulnerability in Pluggabl LLC Booster Plus for WooCommerce.This issue affects Booster Plus for WooCommerce: from n/a before 7.1.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
What the vulnerability does
Missing Authorization vulnerability in Pluggabl LLC Booster Plus for WooCommerce.This issue affects Booster Plus for WooCommerce: from n/a before 7.1.2.
Explanation of Vulnerability in Simple Terms
Booster Plus for WooCommerce versions before 7.1.2 lack proper authorization checks, allowing authenticated users with low privileges to disrupt site availability. An attacker with a basic user account can trigger a denial-of-service condition without requiring user interaction. Update to version 7.1.2 or later to restore proper access controls.
What an attacker can do
Disrupt site availability by exploiting missing authorization checks as a low-privilege authenticated user.
Potential impact on your site
Site availability can be disrupted by any authenticated user, even those with minimal permissions.
Conditions required to exploit
Attacker must have a valid user account with low privileges; no user interaction required.
Key dates
External resources
Related vulnerabilities