Shopping Cart & eCommerce Store <= 5.6.4 - Sensitive Information Exposure
2024-05-10 09:18
rajesh patilStrategic Overview
StatusPatched in 5.6.5
Affected PluginShopping Cart & eCommerce Store
Affected Version
<= 5.6.4CVSS5.3Medium
CVE
CVE-2024-4213Vulnerability Overview
The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.6.4 via the order report functionality. This makes it possible for unauthenticated attackers to extract sensitive data including order details such as payment details, addresses and other PII.
Technical Analysis
REMEDIATION: Update to version 5.6.5, or a newer patched version --- IDENTIFIER: CWE-922 (Insecure Storage of Sensitive Information) The product stores sensitive information without properly limiting read or write access by unauthorized actors.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C