WooCommerce < 5.7.0 & WooCommerce Admin < 2.6.4 - Information Disclosure

2022-04-10 00:00
Anonymous

Strategic Overview

Status
Patched in 4.0.3
Affected PluginWooCommerce
Affected Version4.0 – < 5.6.1 · 18 branches
CVSS6.5Medium
CVEN/A
View all WooCommerce vulnerabilities

Vulnerability Overview

The WooCommerce and WooCommerce Admin plugins for WordPress are vulnerable to Sensitive Data Exposure in versions up to 5.7.0 for WooCommerce and 2.6.4 for WooCommerce Admin due to insufficient protection of analytic report storage in the directory they are stored. This makes it possible for attackers to extract sensitive data related to report analytics on certain host configurations.

Technical Analysis

REMEDIATION: Update to one of the following versions, or a newer patched version: 4.0.3, 4.1.3, 4.2.4, 4.3.5, 4.4.3, 4.5.4, 4.6.4, 4.7.3, 4.8.2, 4.9.4, 5.0.2, 5.1.2, 5.2.4, 5.3.2, 5.4.3, 5.5.3, 5.6.1, 5.7.0 --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C