What the vulnerability does
01Description
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce Shipping Multiple Addresses.This issue affects Shipping Multiple Addresses: from n/a through 3.8.3.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce Shipping Multiple Addresses.This issue affects Shipping Multiple Addresses: from n/a through 3.8.3.
Explanation of Vulnerability in Simple Terms
The Shipping Multiple Addresses plugin for WooCommerce contains an authorization flaw that allows authenticated users to access sensitive shipping data they should not see. An attacker with a low-privilege account can read confidential information about other users' shipping addresses and related details. The vulnerability affects versions up to 3.8.3 and requires a valid user login to exploit.
What an attacker can do
Read other users' shipping addresses and related sensitive shipping data.
Potential impact on your site
Customer shipping data may be exposed to other logged-in users, risking privacy violations and potential data breach liability.
Conditions required to exploit
Attacker must have a valid WooCommerce user account (low privilege level).
Key dates
External resources
Related vulnerabilities