CorreosExpress <= 2.6.0 - Sensitive Data Exposure
2021-11-29 00:00
José AguileraStrategic Overview
StatusUnpatched
Affected PluginCorreosExpress – Shipping Management – Tags
Affected Version
<= 2.6.0CVSS5.3Medium
CVE
CVE-2021-25009Vulnerability Overview
The CorreosExpress WordPress plugin through 2.6.0 generates log files which are publicly accessible, and contain sensitive information such as sender/receiver names, phone numbers, physical and email addresses
Technical Analysis
REMEDIATION: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement. --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C