Lucene search

K
wpvulndbJosé AguileraWPVDB-ID:CE2E3503-9A06-4F5C-AE0F-F40E7DFB2903
HistoryNov 29, 2021 - 12:00 a.m.

CorreosExpress <= 2.6.0 - Sensitive Information Disclosure

2021-11-2900:00:00
José Aguilera
wpscan.com
20
correosexpress
sensitive information
log files
disclosure

EPSS

0.001

Percentile

40.2%

The plugin generates log files which are publicly accessible, and contain sensitive information such as sender/receiver names, phone numbers, physical and email addresses

PoC

https://example.com/wp-content/plugins/correos-express/log/log_cron_function.txt https://example.com/wp-content/plugins/correos-express/log/log_ordenes.txt https://example.com/wp-content/plugins/correos-express/log/log_rest.txt

EPSS

0.001

Percentile

40.2%

Related for WPVDB-ID:CE2E3503-9A06-4F5C-AE0F-F40E7DFB2903