What the vulnerability does
01Description
Improper Privilege Management vulnerability in WPFactory EAN for WooCommerce allows Privilege Escalation.This issue affects EAN for WooCommerce: from n/a through 4.8.9.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Improper Privilege Management vulnerability in WPFactory EAN for WooCommerce allows Privilege Escalation.This issue affects EAN for WooCommerce: from n/a through 4.8.9.
Explanation of Vulnerability in Simple Terms
EAN for WooCommerce versions up to 4.8.9 contain a privilege management flaw that allows high-privileged users to read sensitive data, modify site content, or disrupt service. The vulnerability requires administrator-level access to exploit. Site owners should update to a version newer than 4.8.9 immediately.
What an attacker can do
An administrator can read sensitive data, modify content, or disrupt the site's availability.
Potential impact on your site
Compromised admin accounts can cause data breaches, content tampering, or service outages.
Conditions required to exploit
Attacker must have administrator-level access to the WordPress site.
Key dates
External resources
Related vulnerabilities