What the vulnerability does
01Description
Unauthenticated Broken Access Control in WPC Product Bundles for WooCommerce <= 8.5.3 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
What the vulnerability does
Unauthenticated Broken Access Control in WPC Product Bundles for WooCommerce <= 8.5.3 versions.
Explanation of Vulnerability in Simple Terms
WPC Product Bundles for WooCommerce versions up to 8.5.3 lack proper authorization checks, allowing unauthenticated attackers to modify bundle data over the network. An attacker can alter product bundle configurations without needing to log in or interact with a site administrator. This affects the integrity of product offerings and pricing on WooCommerce stores.
What an attacker can do
Modify product bundle configurations and pricing without authentication.
Potential impact on your site
Attackers can alter your product bundles, prices, and configurations, disrupting sales and customer trust.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities