What the vulnerability does
01Description
Missing Authorization vulnerability in Fahad Mahmood Stock Locations for WooCommerce stock-locations-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Stock Locations for WooCommerce: from n/a through <= 2.8.6.
Explanation of Vulnerability in Simple Terms
02Summary
Stock Locations for WooCommerce versions up to 2.8.6 lack proper authorization checks, allowing authenticated users with low privileges to modify site data and disrupt service availability. An attacker with a basic user account can alter inventory locations and cause the site to become unavailable. Update to a version newer than 2.8.6.
What an attacker can do
03Attacker Capabilities
Modify inventory data and make the site unavailable.
Potential impact on your site
04Site Impact
Inventory data can be corrupted and the site may become inaccessible to customers.
Conditions required to exploit
05Prerequisites
Attacker needs a low-privilege user account (e.g., customer or subscriber role).
Key dates
06Disclosure timeline
June 9, 2025
CVE published
April 28, 2026
Record updated