What the vulnerability does
01Description
Missing Authorization vulnerability in actpro Extra Product Options for WooCommerce.This issue affects Extra Product Options for WooCommerce: from n/a through 3.0.6.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in actpro Extra Product Options for WooCommerce.This issue affects Extra Product Options for WooCommerce: from n/a through 3.0.6.
Explanation of Vulnerability in Simple Terms
Extra Product Options for WooCommerce versions up to 3.0.6 lack proper authorization checks on certain administrative functions. A logged-in user with low privileges can modify product options without proper permission verification. This allows unauthorized changes to product configurations that should be restricted to administrators or shop managers.
What an attacker can do
Modify product options without proper authorization as a low-privilege logged-in user.
Potential impact on your site
Unauthorized users can alter product configurations, potentially disrupting sales, pricing, or product availability.
Conditions required to exploit
Attacker must have a low-privilege user account on the WooCommerce site (e.g., customer or subscriber role).
Key dates
External resources
Related vulnerabilities