Lucene search

K
cvePatchstackCVE-2022-41623
HistoryOct 14, 2022 - 8:15 p.m.

CVE-2022-41623

2022-10-1420:15:16
CWE-202
Patchstack
web.nvd.nist.gov
29
3
villatheme
ald
aliexpress
dropshipping
fulfillment
woocommerce
premium plugin
wordpress
cve-2022-41623
sensitive data exposure
nvd

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.002

Percentile

52.5%

Sensitive Data Exposure in Villatheme ALD - AliExpress Dropshipping and Fulfillment for WooCommerce premium plugin <= 1.1.0 on WordPress.

Affected configurations

Nvd
Vulners
Node
villathemedropshipping_and_fulfillment_for_aliexpress_and_woocommerceRange1.1.0wordpress
VendorProductVersionCPE
villathemedropshipping_and_fulfillment_for_aliexpress_and_woocommerce*cpe:2.3:a:villatheme:dropshipping_and_fulfillment_for_aliexpress_and_woocommerce:*:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "vendor": "Villatheme",
    "product": "ALD - AliExpress Dropshipping and Fulfillment for WooCommerce (WordPress plugin)",
    "versions": [
      {
        "version": "<= 1.1.0",
        "status": "affected",
        "lessThanOrEqual": "1.1.0",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS

0.002

Percentile

52.5%

Related for CVE-2022-41623