PT-2024-29762 · WordPress · Shopping Cart & Ecommerce Store
Rajesh Patil
·
Published
2024-05-10
·
Updated
2024-05-14
·
CVE-2024-4213
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
The Shopping Cart & eCommerce Store plugin for WordPress versions prior to 5.6.5
Description
The issue allows unauthenticated attackers to extract sensitive data, including order details such as payment details, addresses, and other personally identifiable information (PII), via the order report functionality.
Recommendations
For versions prior to 5.6.5, update to version 5.6.5 or later to resolve the issue.
Fix
Insecure Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Shopping Cart & Ecommerce Store