CyberRota Analysis
AI-GeneratedThe WooCommerce Mobile App Builder Service for WordPress is vulnerable due to insufficient capability checks, enabling any authenticated user, including customers and subscribers, to modify stock quantities of any product via its REST endpoints. This flaw could lead to unauthorized inventory manipulation, potentially resulting in financial losses or inventory discrepancies. WordPress site administrators using this plugin should prioritize addressing this vulnerability to safeguard their e-commerce operations.
Original NVD Description
The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 does not check the user's capabilities before allowing a stock-update operation through one of its REST endpoints, allowing any authenticated user, such as a customer or subscriber, to change the stock quantity of arbitrary products.