What the vulnerability does
01Description
Missing Authorization vulnerability in Palscode Multi Currency For WooCommerce.This issue affects Multi Currency For WooCommerce: from n/a through 1.5.5.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
What the vulnerability does
Missing Authorization vulnerability in Palscode Multi Currency For WooCommerce.This issue affects Multi Currency For WooCommerce: from n/a through 1.5.5.
Explanation of Vulnerability in Simple Terms
Multi Currency For WooCommerce versions up to 1.5.5 lack proper authorization checks on certain functions. A logged-in user with low privileges can trigger actions they should not have access to, potentially disrupting site availability. The vulnerability requires valid user credentials but no special interaction from the victim.
What an attacker can do
A low-privilege logged-in user can trigger unauthorized actions that degrade site availability.
Potential impact on your site
Authenticated users may disrupt WooCommerce functionality or availability without proper authorization controls.
Conditions required to exploit
Attacker must have a valid WooCommerce user account with low-level permissions.
Key dates
External resources
Related vulnerabilities