PT-2024-16358 · WordPress · Woo Manage Fraud Orders

Colin Xu

·

Published

2024-10-30

·

Updated

2024-11-04

·

CVE-2024-10544

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Woo Manage Fraud Orders plugin for WordPress versions 6.1.7 and earlier
Description The issue allows unauthenticated attackers to view potentially sensitive information about users contained in publicly exposed log files. This is possible due to sensitive information exposure in the plugin.
Recommendations For versions 6.1.7 and earlier, update to a version later than 6.1.7 to mitigate the risk of sensitive information exposure. As a temporary workaround, consider restricting access to the publicly exposed log files until a patch is available.

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

CVE-2024-10544

Affected Products

Woo Manage Fraud Orders