CVE-2023-52179
Description
Missing Authorization vulnerability in WebCodingPlace Product Expiry for WooCommerce.This issue affects Product Expiry for WooCommerce: from n/a through 2.5.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Missing authorization in Product Expiry for WooCommerce ≤2.5 allows unauthenticated or low-privileged users to exploit broken access control.
Vulnerability
Overview The Product Expiry for WooCommerce plugin for WordPress versions through 2.5 suffers from a missing authorization vulnerability. This broken access control issue occurs because certain functions lack proper nonce or capability checks, allowing unauthenticated or low-privileged users to execute actions intended for higher-privileged roles [1].
Exploitation
Details This vulnerability is classified as broken access control and is known to be used in mass-exploit campaigns targeting thousands of websites regardless of size [1]. The CVSS score of 5.4 (Medium) reflects the potential for exploitation without complex prerequisites, though the vendor considers it low severity and unlikely to be actively exploited [1].
Impact
An attacker exploiting this flaw can perform unauthorized operations within the plugin, potentially disrupting product expiry settings or accessing sensitive functionality [1]. The exact impact scope depends on the missing authorization check, but it undermines the intended privilege separation.
Mitigation
To remediate, update the plugin to version 2.6 or later, where the authorization check is enforced [1]. Patchstack users can enable auto-updates for vulnerable plugins. For sites unable to update immediately, consult a hosting provider or web developer for assistance [1].
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <=2.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.