WordPress Simple PayPal Shopping Cart <= 5.1.2 - Unauthenticated Information Exposure via file_url Parameter

2025-04-22 19:00
Jack Taylor

Strategic Overview

Status
Patched in 5.1.3
Affected PluginSimple Shopping Cart
Affected Version<= 5.1.2
CVSS8.2High
CVECVE-2025-3529
View all Simple Shopping Cart vulnerabilities

Vulnerability Overview

The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.1.2 via the 'file_url' parameter. This makes it possible for unauthenticated attackers to view potentially sensitive information and download a digital product without paying for it.

Technical Analysis

REMEDIATION: Update to version 5.1.3, or a newer patched version --- IDENTIFIER: CWE-201 (Insertion of Sensitive Information Into Sent Data) The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C