What the vulnerability does
01Description
Missing Authorization vulnerability in Uriahs Victor Location Picker at Checkout for WooCommerce.This issue affects Location Picker at Checkout for WooCommerce: from n/a through 1.8.9.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Uriahs Victor Location Picker at Checkout for WooCommerce.This issue affects Location Picker at Checkout for WooCommerce: from n/a through 1.8.9.
Explanation of Vulnerability in Simple Terms
The Location Picker at Checkout for WooCommerce plugin through version 1.8.9 does not properly check user permissions before allowing modifications to location data. A logged-in user with low privileges can alter location settings that should be restricted to administrators, potentially affecting checkout behavior and customer experience.
What an attacker can do
A logged-in user can modify location settings they should not have access to.
Potential impact on your site
Unauthorized users could change checkout location settings, disrupting the checkout process or exposing unintended location data.
Conditions required to exploit
Attacker must have a low-privilege account on the site (e.g., customer or subscriber role).
Key dates
External resources
Related vulnerabilities