VYPR
Medium severity5.4NVD Advisory· Published Jun 11, 2024· Updated Apr 15, 2026

CVE-2023-52179

CVE-2023-52179

Description

Missing Authorization vulnerability in WebCodingPlace Product Expiry for WooCommerce.This issue affects Product Expiry for WooCommerce: from n/a through 2.5.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Missing authorization in Product Expiry for WooCommerce ≤2.5 allows unauthenticated or low-privileged users to exploit broken access control.

Vulnerability

Overview The Product Expiry for WooCommerce plugin for WordPress versions through 2.5 suffers from a missing authorization vulnerability. This broken access control issue occurs because certain functions lack proper nonce or capability checks, allowing unauthenticated or low-privileged users to execute actions intended for higher-privileged roles [1].

Exploitation

Details This vulnerability is classified as broken access control and is known to be used in mass-exploit campaigns targeting thousands of websites regardless of size [1]. The CVSS score of 5.4 (Medium) reflects the potential for exploitation without complex prerequisites, though the vendor considers it low severity and unlikely to be actively exploited [1].

Impact

An attacker exploiting this flaw can perform unauthorized operations within the plugin, potentially disrupting product expiry settings or accessing sensitive functionality [1]. The exact impact scope depends on the missing authorization check, but it undermines the intended privilege separation.

Mitigation

To remediate, update the plugin to version 2.6 or later, where the authorization check is enforced [1]. Patchstack users can enable auto-updates for vulnerable plugins. For sites unable to update immediately, consult a hosting provider or web developer for assistance [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.