What the vulnerability does
01Description
Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.1 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
What the vulnerability does
Unauthenticated Broken Access Control in StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.1 versions.
Explanation of Vulnerability in Simple Terms
StoreGrowth for WooCommerce versions up to 2.1.1 lack proper authorization checks, allowing unauthenticated attackers to modify store data without permission. An attacker can change product information, pricing, or other critical settings by sending direct requests to the plugin. No user interaction or special access is required. Site owners should update immediately to a patched version.
What an attacker can do
Modify store data, pricing, or product settings without logging in.
Potential impact on your site
Attackers can alter product prices, descriptions, or other store configuration without your knowledge or consent.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities