PushEngage – Web Push Notifications, WooCommerce Automation & Chat Widget <= 4.2.3 - Authenticated (Subscriber+) Information Exposure
mediumThe PushEngage – Web Push Notifications, WooCommerce Automation & Chat Widget plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or configu...
- CVSS:
- 4.3
- Affected:
- up to 4.2.3
- Fixed in:
- 4.2.4
- Disclosed:
- Jun 10, 2026