What the vulnerability does
01Description
Missing Authorization vulnerability in Mr.Ebabi New Order Notification for Woocommerce.This issue affects New Order Notification for Woocommerce: from n/a through 2.0.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
What the vulnerability does
Missing Authorization vulnerability in Mr.Ebabi New Order Notification for Woocommerce.This issue affects New Order Notification for Woocommerce: from n/a through 2.0.2.
Explanation of Vulnerability in Simple Terms
The New Order Notification for WooCommerce plugin fails to properly check user permissions before allowing access to sensitive order notification functions. An authenticated user with low privileges can read and modify order data and notification settings they should not have access to. This affects versions up to 2.0.2.
What an attacker can do
Read and modify order data and notification settings belonging to other users or the store.
Potential impact on your site
Customer order information and notification configurations can be accessed or altered by unauthorized users with site accounts.
Conditions required to exploit
Attacker must have a low-privilege account on the WooCommerce site (e.g., customer or subscriber role).
Key dates
External resources
Related vulnerabilities