Shopping Cart & eCommerce Store <= 5.6.4 - Sensitive Information Exposure

2024-05-10 09:18
rajesh patil

Strategic Overview

Status
Patched in 5.6.5
Affected Version<= 5.6.4
CVSS5.3Medium
CVECVE-2024-4213
View all Shopping Cart & eCommerce Store vulnerabilities

Vulnerability Overview

The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.6.4 via the order report functionality. This makes it possible for unauthenticated attackers to extract sensitive data including order details such as payment details, addresses and other PII.

Technical Analysis

REMEDIATION: Update to version 5.6.5, or a newer patched version --- IDENTIFIER: CWE-922 (Insecure Storage of Sensitive Information) The product stores sensitive information without properly limiting read or write access by unauthorized actors.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C