The WooCommerce Multivendor Marketplace – REST API plugin for WordPress is vulnerable to unauthorized access of data and addition of data due to a missing capability check on the 'get_item', 'get_order_notes' and 'add_order_note' functions in versions up to, and including, 1.5.3. This makes it possible for authenticated attackers with subscriber privileges or above, to view the order details and order notes, and add order notes.
CVE ID: CVE-2023-2275
CVSS Base Severity: MEDIUM
CVSS Base Score: 4.3
Vendor: wclovers
Product: WooCommerce Multivendor Marketplace – REST API
EPSS Score: 0.09% (probability of being exploited)
EPSS Percentile: 38.39% (scored less or equal to compared to others)
EPSS Date: 2025-02-04 (when was this score calculated)