WordPress Simple PayPal Shopping Cart <= 5.1.2 - Unauthenticated Information Exposure via file_url Parameter
2025-04-22 19:00
Jack TaylorStrategic Overview
StatusPatched in 5.1.3
Affected PluginSimple Shopping Cart
Affected Version
<= 5.1.2CVSS8.2High
CVE
CVE-2025-3529Vulnerability Overview
The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.1.2 via the 'file_url' parameter. This makes it possible for unauthenticated attackers to view potentially sensitive information and download a digital product without paying for it.
Technical Analysis
REMEDIATION: Update to version 5.1.3, or a newer patched version --- IDENTIFIER: CWE-201 (Insertion of Sensitive Information Into Sent Data) The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C