What the vulnerability does
01Description
Missing Authorization vulnerability in Andreas Sofantzis Simple COD Fees for WooCommerce.This issue affects Simple COD Fees for WooCommerce: from n/a through 2.0.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Missing Authorization vulnerability in Andreas Sofantzis Simple COD Fees for WooCommerce.This issue affects Simple COD Fees for WooCommerce: from n/a through 2.0.2.
Explanation of Vulnerability in Simple Terms
The Simple COD Fees for WooCommerce plugin through version 2.0.2 lacks proper authorization checks on certain administrative functions. A logged-in user with low privileges can modify plugin settings and data without proper permission validation, potentially affecting order processing and site configuration.
What an attacker can do
A low-privilege user can modify plugin settings and order data without authorization.
Potential impact on your site
Unauthorized users could alter COD fees, payment settings, or order information, disrupting checkout and order management.
Conditions required to exploit
Attacker must have a low-privilege account on the site (e.g., customer or subscriber role).
Key dates
External resources
Related vulnerabilities