What the vulnerability does
01Description
Missing Authorization vulnerability in WPClever WPC Frequently Bought Together for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPC Frequently Bought Together for WooCommerce: from n/a through 7.1.9.
Explanation of Vulnerability in Simple Terms
02Summary
WPC Frequently Bought Together for WooCommerce versions up to 7.1.9 lack proper authorization checks on certain functions. A logged-in user with low privileges can read or modify data they should not have access to. Update to a version newer than 7.1.9 to resolve this issue.
What an attacker can do
03Attacker Capabilities
Read or modify WooCommerce data without proper authorization as a low-privilege user.
Potential impact on your site
04Site Impact
Unauthorized users can access or alter product recommendations and related WooCommerce settings.
Conditions required to exploit
05Prerequisites
Attacker must have a valid WordPress user account with low privileges (e.g., subscriber or customer role).
Key dates
06Disclosure timeline
November 1, 2024
CVE published
April 28, 2026
Record updated