CorreosExpress <= 2.6.0 - Sensitive Data Exposure
mediumThe CorreosExpress WordPress plugin through 2.6.0 generates log files which are publicly accessible, and contain sensitive information such as sender/receiver names, phone numbers, physical and email addresses
- CVSS:
- 5.3
- Affected:
- up to 2.6.0
- Fix:
- No patched version reported
- Disclosed:
- Nov 29, 2021