Japanized for WooCommerce
cpe:2.3:a:artisanworkshop:japanized_for_woocommerce:*:*:*:*:wordpress:*:*
- <= 2.7.17
A vulnerability exists in the Japanized for WooCommerce plugin for WordPress, all versions through 2.7.17, allowing unauthorized data modification. The issue arises from a missing capability check on the 'order' REST API endpoint, enabling unauthenticated attackers to change the status of any WooCommerce order to processed or completed.
Exploitation of this vulnerability allows for unauthorized modification of order statuses, potentially disrupting order management and fulfillment processes.
Users are advised to update the Japanized for WooCommerce plugin to version 2.8.0 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.