Lucene search

K
wpvulndbWpvulndbWPVDB-ID:3D821963-F2BF-4B8D-BC2D-296790F5E1DD
HistoryOct 27, 2023 - 12:00 a.m.

Soisy Pagamento Rateale <= 6.0.1 - Missing Authorization to Sensitive Information Exposure

2023-10-2700:00:00
wpscan.com
3
missing authorization
sensitive information exposure
woocommerce order

AI Score

6.2

Confidence

High

EPSS

0.001

Percentile

39.8%

Description The plugin does not properly validate authorization in calls to the parseRemoteRequest function allowing unauthenticated visitors with knowledge of an existing WooCommerce Order ID to expose sensitive WooCommerce order information (e.g., Name, Address, Email Address, and other order metadata).

AI Score

6.2

Confidence

High

EPSS

0.001

Percentile

39.8%

Related for WPVDB-ID:3D821963-F2BF-4B8D-BC2D-296790F5E1DD