What the vulnerability does
01Description
Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.
Explanation of Vulnerability in Simple Terms
The Kadence WooCommerce Email Designer plugin through version 1.5.19 lacks proper authorization checks, allowing unauthenticated attackers to read, modify, or delete sensitive data and functionality. An attacker can exploit this over the network without special conditions. This affects all installations running the vulnerable version.
What an attacker can do
Read, modify, or delete site data and email templates without logging in.
Potential impact on your site
Attackers can compromise email campaigns, steal customer data, and disrupt WooCommerce operations without any credentials.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities