PT-2023-16978 · WordPress · Wp Simple Shopping Cart
Ayoub Safa
·
Published
2023-03-16
·
Updated
2023-03-22
·
CVE-2023-1431
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WP Simple Shopping Cart plugin for WordPress versions up to, and including, 4.6.3
Description
The issue allows unauthenticated attackers to view sensitive information that should be limited to administrators only. This information can include
first name, last name, email, address, IP Address, and more. The problem arises because the plugin saves shopping cart data exports in a publicly accessible location, specifically at the /wp-content/plugins/wordpress-simple-paypal-shopping-cart/includes/admin/ endpoint.Recommendations
For WP Simple Shopping Cart plugin for WordPress versions up to, and including, 4.6.3, consider restricting access to the
/wp-content/plugins/wordpress-simple-paypal-shopping-cart/includes/admin/ endpoint until a patch is available. As a temporary workaround, avoid using the plugin's data export feature to minimize the risk of sensitive information exposure. Update to a version later than 4.6.3 when available.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wp Simple Shopping Cart