PT-2024-16311 · Google · Google For Woocommerce

Francesco Carlucci

·

Published

2024-11-18

·

Updated

2025-04-04

·

CVE-2024-10486

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Google for WooCommerce plugin for WordPress versions up to, and including, 2.8.6
Description The issue is related to an Information Disclosure vulnerability due to a publicly accessible print php information.php file. This allows unauthenticated attackers to retrieve information about the web server and PHP configuration, which can aid other attacks.
Recommendations For Google for WooCommerce plugin for WordPress versions up to, and including, 2.8.6: Update to the latest version to protect your site. At the moment, there is no information about other specific mitigation measures for this vulnerability.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-10486

Affected Products

Google For Woocommerce