What the vulnerability does
01Description
Missing Authorization vulnerability in Bosa Themes Bosa Elementor Addons and Templates for WooCommerce.This issue affects Bosa Elementor Addons and Templates for WooCommerce: from n/a through 1.0.12.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Bosa Themes Bosa Elementor Addons and Templates for WooCommerce.This issue affects Bosa Elementor Addons and Templates for WooCommerce: from n/a through 1.0.12.
Explanation of Vulnerability in Simple Terms
Bosa Elementor Addons and Templates for WooCommerce versions up to 1.0.12 lack proper authorization checks on certain functions. A logged-in user with low privileges can modify data they should not have access to. The vulnerability does not affect data confidentiality or site availability, but allows unauthorized changes to site content or settings.
What an attacker can do
A logged-in user can modify data or settings they should not have permission to change.
Potential impact on your site
Unauthorized users may alter WooCommerce product data, Elementor templates, or plugin settings without your permission.
Conditions required to exploit
Attacker must have a low-privilege account on the site (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities