What the vulnerability does
01Description
Missing Authorization vulnerability in ThemeLocation Custom WooCommerce Checkout Fields Editor.This issue affects Custom WooCommerce Checkout Fields Editor: from n/a through 1.3.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in ThemeLocation Custom WooCommerce Checkout Fields Editor.This issue affects Custom WooCommerce Checkout Fields Editor: from n/a through 1.3.0.
Explanation of Vulnerability in Simple Terms
The Custom WooCommerce Checkout Fields Editor plugin through version 1.3.0 does not properly check user permissions before allowing modifications to checkout fields. A logged-in user with low privileges can alter checkout field settings that should be restricted to administrators, potentially changing form behavior or data collection without authorization.
What an attacker can do
Modify WooCommerce checkout field settings without proper authorization.
Potential impact on your site
Unauthorized users can alter your checkout form fields, potentially disrupting transactions or collecting unintended customer data.
Conditions required to exploit
Attacker must have a low-privilege user account on the site (e.g., customer or subscriber role).
Key dates
External resources
Related vulnerabilities