WordPress WC Pickup Store Missing Authorization Vulnerability Allowing Access Control Bypass

Vulnerability

A missing authorization vulnerability has been identified in the WordPress WC Pickup Store plugin, specifically in versions through 1.8.9. This vulnerability allows for the exploitation of incorrectly configured access control security levels, potentially leading to unauthorized changes in settings.

Impact

Exploitation of this vulnerability could result in unauthorized changes to settings, allowing attackers to manipulate configuration options without proper authorization.

Remediation

Users of the WC Pickup Store plugin are advised to update to the latest version. For those using WordPress, Patchstack offers a virtual patch that automatically mitigates this vulnerability by blocking attacks until an official fix is available.

Added: Jul 4, 2025, 1:13 PM
Updated: Jul 4, 2025, 1:13 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
7.4
remediation
0.0
relevance
0.2
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.