WooCommerce < 5.7.0 & WooCommerce Admin < 2.6.4 - Information Disclosure
mediumThe WooCommerce and WooCommerce Admin plugins for WordPress are vulnerable to Sensitive Data Exposure in versions up to 5.7.0 for WooCommerce and 2.6.4 for WooCommerce Admin due to insufficient protection of analytic report storage in the directory they are stored. This makes it possible for attackers to extract sensit...
- CVSS:
- 6.5
- Affected:
- up to 1.0, 1.0 – 1.0.4, 1.1 – 1.1.4, 1.2 – 1.2.5, 1.3 – 1.3.3, 1.4 – 1.4.1, 1.5 – 1.5.1, 1.6 – 1.6.4, 1.7 – 1.7.4, 1.8 – 1.8.4, 1.9 – 1.9.1, 2.0 – 2.0.4, 2.1 – 2.1.6, 2.2 – 2.2.7, 2.3 – 2.3.2, 2.4 – 2.4.5, 2.5 – 2.5.2, 2.6 – 2.6.4
- Fixed in:
- 1.0.4
- Disclosed:
- Apr 10, 2022