CVE-2023-4796 MEDIUM

CVE-2023-4796: Booster for WooCommerce <= 7.1.0 - Authenticated (Subscriber+) Information Disclosure via Shortcode

Vendor Pluggabl
Product Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools
Weakness CWE-200 · Info exposure
Published October 20, 2023
Last update April 8, 2026

CVSS base score

4.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

The Booster for WooCommerce for WordPress is vulnerable to Information Disclosure via the 'wcj_wp_option' shortcode in versions up to, and including, 7.1.0 due to insufficient controls on the information retrievable via the shortcode. This makes it possible for authenticated attackers, with subscriber-level capabilities or above, to retrieve arbitrary sensitive site options.

Explanation of Vulnerability in Simple Terms

02Summary

The Booster for WooCommerce plugin versions up to 7.1.0 expose sensitive information to authenticated users with low privileges. An attacker with a basic user account can access data they should not be able to view. The vulnerability stems from insufficient access controls on certain data endpoints. Update to a version newer than 7.1.0 to resolve this issue.

What an attacker can do

03Attacker Capabilities

Read sensitive information accessible only to higher-privilege users or other site users.

Potential impact on your site

04Site Impact

Customer data, order details, or other sensitive information may be exposed to low-privilege user accounts.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege user account on the site (e.g., subscriber or customer role).

Key dates

06Disclosure timeline

October 20, 2023 CVE published
April 8, 2026 Record updated

Related vulnerabilities

08Related CVE