What the vulnerability does
01Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pluggabl LLC Booster for WooCommerce plugin <= 7.1.1 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pluggabl LLC Booster for WooCommerce plugin <= 7.1.1 versions.
Explanation of Vulnerability in Simple Terms
Booster for WooCommerce versions up to 7.1.1 expose sensitive information to authenticated users. A logged-in user with low privileges can read data they should not have access to. The vulnerability does not allow modification or deletion of data, only unauthorized viewing. Update to a version newer than 7.1.1 to resolve this issue.
What an attacker can do
Read sensitive information they should not have access to.
Potential impact on your site
Customer data or other sensitive information may be exposed to low-privilege users on your WooCommerce site.
Conditions required to exploit
Attacker must be logged in to the site with a low-privilege account (e.g., customer or subscriber).
Key dates
External resources
Related vulnerabilities