WPGraphQL WooCommerce <= 0.12.3 - Information Disclosure
mediumThe WPGraphQL WooCommerce plugin for WordPress is vulnerable to Information Exposure in versions up to, and including, 0.12.3. This can allow unauthenticated attackers to extract coupon codes via GraphQL.
- CVSS:
- 5.3
- Affected:
- up to 0.12.3
- Fixed in:
- 0.12.4
- Disclosed:
- Jul 26, 2022