What the vulnerability does
01Description
Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
What the vulnerability does
Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions.
Explanation of Vulnerability in Simple Terms
The Mobile App for WooCommerce fails to properly check user permissions before allowing access to sensitive functions. An attacker on the network can read and modify data without authentication. This affects all versions up to 0.4.62. Site owners should update immediately and review access logs for unauthorized activity.
What an attacker can do
Read and modify WooCommerce data without logging in.
Potential impact on your site
Unauthorized users can access and alter orders, customer data, and store settings.
Conditions required to exploit
Network access to the mobile app; no authentication required.
Key dates
External resources
Related vulnerabilities