What the vulnerability does
01Description
Missing Authorization vulnerability in ThemeSupport Hide Category by User Role for WooCommerce hide-category-by-user-role-for-woocommerce.This issue affects Hide Category by User Role for WooCommerce: from n/a through <= 2.1.1.
Explanation of Vulnerability in Simple Terms
02Summary
The Hide Category by User Role for WooCommerce plugin through version 2.1.1 does not properly check user permissions before allowing modifications to category visibility settings. A logged-in user with low privileges can change which product categories are hidden or shown to other user roles, potentially exposing or restricting access to products unintentionally.
What an attacker can do
03Attacker Capabilities
Modify product category visibility settings for other user roles without proper authorization.
Potential impact on your site
04Site Impact
Product categories may be exposed or hidden incorrectly, disrupting intended access controls and potentially affecting sales or user experience.
Conditions required to exploit
05Prerequisites
Attacker must be logged in with a low-privilege account (e.g., subscriber or customer).
Key dates
06Disclosure timeline
January 7, 2025
CVE published
April 28, 2026
Record updated