What the vulnerability does
01Description
Missing Authorization vulnerability in WP Desk Flexible Checkout Fields for WooCommerce.This issue affects Flexible Checkout Fields for WooCommerce: from n/a through 4.1.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in WP Desk Flexible Checkout Fields for WooCommerce.This issue affects Flexible Checkout Fields for WooCommerce: from n/a through 4.1.2.
Explanation of Vulnerability in Simple Terms
Flexible Checkout Fields for WooCommerce versions up to 4.1.2 lack proper authorization checks on certain operations. A logged-in user with low privileges can modify checkout field settings without proper permission validation. This allows unauthorized changes to how checkout fields are configured on the site.
What an attacker can do
Modify checkout field settings without proper authorization.
Potential impact on your site
Unauthorized users can alter checkout field configuration, potentially disrupting the checkout process or exposing sensitive data fields.
Conditions required to exploit
Attacker must be logged in with a low-privilege account (e.g., customer or subscriber).
Key dates
External resources
Related vulnerabilities