What the vulnerability does
01Description
Unauthenticated Sensitive Information Disclosure vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Unauthenticated Sensitive Information Disclosure vulnerability in Customer Reviews for WooCommerce plugin <= 5.3.5 at WordPress
Explanation of Vulnerability in Simple Terms
The Customer Reviews for WooCommerce plugin through version 5.3.5 exposes sensitive information to unauthenticated users. An attacker can read data that should be restricted without needing to log in or interact with a site owner. The vulnerability stems from insufficient access controls on data endpoints.
What an attacker can do
Read sensitive information from the plugin without authentication.
Potential impact on your site
Customer or site data may be visible to anyone on the internet without logging in.
Conditions required to exploit
Network access to the WordPress site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities