What the vulnerability does
01Description
Missing Authorization vulnerability in Dotstore Hide Shipping Method For WooCommerce hide-shipping-method-for-woocommerce.This issue affects Hide Shipping Method For WooCommerce: from n/a through <= 1.5.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Missing Authorization vulnerability in Dotstore Hide Shipping Method For WooCommerce hide-shipping-method-for-woocommerce.This issue affects Hide Shipping Method For WooCommerce: from n/a through <= 1.5.1.
Explanation of Vulnerability in Simple Terms
The Hide Shipping Method For WooCommerce plugin through version 1.5.1 lacks proper authorization checks on certain administrative functions. A logged-in user with low privileges can modify shipping method settings without proper permission validation. This allows unauthorized changes to store shipping configuration that should be restricted to administrators.
What an attacker can do
Modify WooCommerce shipping method settings without proper authorization.
Potential impact on your site
Unauthorized users can alter your store's shipping methods and rules, potentially disrupting orders or hiding legitimate shipping options.
Conditions required to exploit
Attacker must be logged in to the site with a low-privilege user account (e.g., customer or subscriber).
Key dates
External resources
Related vulnerabilities