
CVE-2022-41655 – WordPress Phone Orders for WooCommerce plugin <= 3.7.1 - Auth. Sensitive Data Exposure vulnerability
https://notcve.org/view.php?id=CVE-2022-41655
24 Oct 2022 — Auth. (subscriber+) Sensitive Data Exposure vulnerability in Phone Orders for WooCommerce plugin <= 3.7.1 on WordPress. Vulnerabilidad de exposición de datos confidenciales autenticada (con permisos de suscriptores o superiores) en el complemento Phone Orders para WooCommerce en WordPress en versiones <= 3.7.1. The Phone Orders for WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_gate function which controls many additional functions als... • https://patchstack.com/database/vulnerability/phone-orders-for-woocommerce/wordpress-phone-orders-for-woocommerce-plugin-3-7-1-auth-sensitive-data-exposure-vulnerability?_s_id=cve • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-862: Missing Authorization •