What the vulnerability does
01Description
The Booster for WooCommerce for WordPress is vulnerable to Information Disclosure via the 'wcj_wp_option' shortcode in versions up to, and including, 7.1.0 due to insufficient controls on the information retrievable via the shortcode. This makes it possible for authenticated attackers, with subscriber-level capabilities or above, to retrieve arbitrary sensitive site options.
Explanation of Vulnerability in Simple Terms
02Summary
The Booster for WooCommerce plugin versions up to 7.1.0 expose sensitive information to authenticated users with low privileges. An attacker with a basic user account can access data they should not be able to view. The vulnerability stems from insufficient access controls on certain data endpoints. Update to a version newer than 7.1.0 to resolve this issue.
What an attacker can do
03Attacker Capabilities
Read sensitive information accessible only to higher-privilege users or other site users.
Potential impact on your site
04Site Impact
Customer data, order details, or other sensitive information may be exposed to low-privilege user accounts.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege user account on the site (e.g., subscriber or customer role).
Key dates
06Disclosure timeline
October 20, 2023
CVE published
April 8, 2026
Record updated