Advanced Woo Search <= 2.00 - Information Disclosure
2020-04-23 00:00
AnonymousStrategic Overview
StatusPatched in 2.00
Affected PluginAdvanced Woo Search – Product Search for WooCommerce
Affected Version
<= 1.99CVSS5.3Medium
CVE
CVE-2020-12070Vulnerability Overview
The Advanced Woo Search plugin version through 1.99 for Wordpress suffers from a sensitive information disclosure vulnerability in every ajax search request via the sql field to includes/class-aws-search.php.
Technical Analysis
REMEDIATION: Update to version 2.00, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C