Unauthorized Data Access in WooCommerce Multivendor Marketplace by WCFM
CVE-2023-2275
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 9 June 2023
What is CVE-2023-2275?
The WooCommerce Multivendor Marketplace β REST API plugin for WordPress suffers from an access control vulnerability due to inadequate capability checks on key functions such as 'get_item', 'get_order_notes', and 'add_order_note'. This security oversight allows authenticated users with subscriber roles or higher to gain unauthorized access to sensitive order details and notes, as well as to append additional notes to orders. This vulnerability affects versions through 1.5.3, posing a risk to data integrity and confidentiality in e-commerce environments.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WooCommerce Multivendor Marketplace β REST API * <= 1.5.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved