Executive brief
The Bizswoop Account Manager for WooCommerce plugin, which helps manage customer accounts on WordPress e-commerce sites, contains a security flaw in its access control settings. This vulnerability allows logged-in users with low-level permissions to bypass intended security restrictions and potentially access information or perform actions they should not be authorized to do. This could lead to unauthorized data exposure or interference with store management functions.
Technical details
A missing authorization vulnerability (CWE-862) exists in the Bizswoop Account Manager for WooCommerce plugin for WordPress through version 2.1.2. The flaw stems from incorrectly configured access control security levels within the plugin's account management functions. An authenticated attacker with Subscriber-level privileges can exploit this lack of enforcement to bypass intended restrictions. This could allow for unauthorized access to sensitive data or the execution of restricted administrative actions. As of the latest advisory, no official patch has been released by the vendor, though third-party mitigation rules may be available.
Affected products
- Bizswoop Account Manager for WooCommerce n/a through 2.1.2
Timeline
- 2022-10-13: disclosed: Vulnerability reported by ptsfence and published on Patchstack
- 2026-05-27: advisory: CVE published in the National Vulnerability Database (NVD)