What the vulnerability does
01Description
Unauthenticated Arbitrary File Read vulnerability in MultiSafepay plugin for WooCommerce plugin <= 4.13.1 at WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Unauthenticated Arbitrary File Read vulnerability in MultiSafepay plugin for WooCommerce plugin <= 4.13.1 at WordPress.
Explanation of Vulnerability in Simple Terms
The MultiSafepay plugin for WooCommerce versions up to 4.13.1 exposes sensitive payment information to unauthenticated attackers over the network. An attacker can read partial data without authentication or user interaction. The vulnerability stems from insufficient access controls on payment-related endpoints. Site owners should update immediately to a version newer than 4.13.1.
What an attacker can do
Read sensitive payment information without logging in.
Potential impact on your site
Customer payment data may be exposed to unauthorized parties.
Conditions required to exploit
Network access to the WordPress site; no authentication required.
Key dates
External resources