1 results (0.011 seconds)

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 0

Auth. (subscriber+) Sensitive Data Exposure vulnerability in Phone Orders for WooCommerce plugin <= 3.7.1 on WordPress. Vulnerabilidad de exposición de datos confidenciales autenticada (con permisos de suscriptores o superiores) en el complemento Phone Orders para WooCommerce en WordPress en versiones &lt;= 3.7.1. The Phone Orders for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_gate function which controls many additional functions also missing capability checks, in versions up to, and including, 3.7.1. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to obtain order information and other sensitive data. • https://patchstack.com/database/vulnerability/phone-orders-for-woocommerce/wordpress-phone-orders-for-woocommerce-plugin-3-7-1-auth-sensitive-data-exposure-vulnerability?_s_id=cve https://wordpress.org/plugins/phone-orders-for-woocommerce/#developers • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-862: Missing Authorization •