What the vulnerability does
01Description
Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions.
Explanation of Vulnerability in Simple Terms
The Order Delivery Date for WooCommerce plugin through version 4.6.0 contains a privilege assignment flaw that allows high-privileged users to read, modify, or delete sensitive data and site functionality. The vulnerability requires administrator-level access and does not require user interaction. Site owners should update to a version newer than 4.6.0 to remediate the issue.
What an attacker can do
A high-privileged user can read, modify, or delete sensitive data and disable site functionality.
Potential impact on your site
Administrators with compromised credentials could cause data loss, site defacement, or service disruption.
Conditions required to exploit
Attacker must have administrator-level access to the WordPress site.
Key dates
External resources
Related vulnerabilities