What the vulnerability does
01Description
Missing Authorization vulnerability in weDevs WooCommerce Conversion Tracking.This issue affects WooCommerce Conversion Tracking: from n/a through 2.0.11.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in weDevs WooCommerce Conversion Tracking.This issue affects WooCommerce Conversion Tracking: from n/a through 2.0.11.
Explanation of Vulnerability in Simple Terms
WooCommerce Conversion Tracking by weDevs versions up to 2.0.11 lack proper authorization checks on certain functions. A logged-in user with low privileges can modify data they should not have access to. The vulnerability does not expose sensitive information or disrupt site availability, but allows unauthorized changes to tracking or conversion settings.
What an attacker can do
Modify WooCommerce conversion tracking data or settings without proper authorization.
Potential impact on your site
Unauthorized users can alter conversion tracking configuration, potentially corrupting analytics or reporting data.
Conditions required to exploit
Attacker must have a low-privilege account (e.g., subscriber or customer) on the WordPress site.
Key dates
External resources
Related vulnerabilities