What the vulnerability does
01Description
Auth. (subscriber+) Sensitive Data Exposure vulnerability in Phone Orders for WooCommerce plugin <= 3.7.1 on WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Auth. (subscriber+) Sensitive Data Exposure vulnerability in Phone Orders for WooCommerce plugin <= 3.7.1 on WordPress.
Explanation of Vulnerability in Simple Terms
The Phone Orders for WooCommerce plugin through version 3.7.1 exposes sensitive order information to authenticated users who should not have access to it. A logged-in user with low privileges can view order details they do not own. The vulnerability stems from insufficient access controls on order data endpoints. Update to a version newer than 3.7.1 to resolve this issue.
What an attacker can do
View order details and sensitive information belonging to other customers.
Potential impact on your site
Customer order data and personal information may be exposed to other logged-in users, risking privacy violations and customer trust.
Conditions required to exploit
Attacker must be logged in to the WordPress site with a low-privilege account (e.g., subscriber or customer).
Key dates
External resources
Related vulnerabilities