What the vulnerability does
01Description
The vulnerability discovered in WordPress Perfect Brands for WooCommerce plugin (versions <= 2.0.4) allows server information exposure.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
The vulnerability discovered in WordPress Perfect Brands for WooCommerce plugin (versions <= 2.0.4) allows server information exposure.
Explanation of Vulnerability in Simple Terms
The Perfect Brands for WooCommerce plugin through version 2.0.4 exposes sensitive information to authenticated users. A logged-in user with low privileges can access data they should not be able to view. The exposure is limited to information disclosure with no ability to modify or disable site functionality.
What an attacker can do
Read sensitive data that should be restricted from their user role.
Potential impact on your site
Customer or subscriber accounts can view restricted product or brand information not intended for their role.
Conditions required to exploit
Attacker must be logged in to the WordPress site with a low-privilege account (e.g., subscriber or customer).
Key dates
External resources
Related vulnerabilities