CVE-2025-47602
Description
Missing Authorization vulnerability in ammarahmad786 Calculate Prices based on Distance For WooCommerce calculate-prices-based-on-distance-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Calculate Prices based on Distance For WooCommerce: from n/a through <= 1.3.5.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Missing authorization vulnerability in WordPress Calculate Prices based on Distance plugin allows unprivileged users to access higher privileged functions, patched in version 1.3.6.
The vulnerability is a missing authorization check in the WordPress plugin 'Calculate Prices based on Distance For WooCommerce' (versions <=1.3.5). This allows exploitation of incorrectly configured access control security levels, meaning functions that should require higher privileges are accessible to lower-privileged users or even unauthenticated visitors [1].
An attacker can exploit this by sending crafted requests to vulnerable endpoints without proper capability checks. No authentication is required, making it possible for anyone with access to the site to trigger the vulnerability. The attack surface is any WordPress site running the affected plugin version [1].
Successful exploitation enables an attacker to perform actions that should be restricted, such as modifying plugin settings or accessing sensitive data. This could lead to unauthorized changes in price calculations or other administrative functions, potentially affecting e-commerce operations [1].
The vendor has patched the issue in version 1.3.6. Users are strongly advised to update immediately. Patchstack users can enable auto-updates for vulnerable plugins. The vulnerability is considered low severity but is still a risk for sites using affected versions [1].
AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.