CVE-2023-52230 MEDIUM

CVE-2023-52230: WordPress Booster Plus for WooCommerce plugin < 7.1.3 - Authenticated Arbitrary WordPress Option Disclosure Vulnerability

Vendor Pluggabl Llc
Product Booster Plus for WooCommerce
Weakness CWE-862 · Missing authorization
Published June 9, 2024
Last update April 28, 2026

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

Missing Authorization vulnerability in Pluggabl LLC Booster Plus for WooCommerce.This issue affects Booster Plus for WooCommerce: from n/a before 7.1.3.

Explanation of Vulnerability in Simple Terms

02Summary

Booster Plus for WooCommerce versions before 7.1.3 lack proper authorization checks, allowing authenticated users with low privileges to read sensitive data they should not access. An attacker with a basic user account can retrieve confidential information from the plugin without additional interaction. Update to version 7.1.3 or later to fix this vulnerability.

What an attacker can do

03Attacker Capabilities

Read sensitive data from the plugin that should be restricted to higher-privilege users.

Potential impact on your site

04Site Impact

Customer or subscriber accounts can access confidential plugin data, risking exposure of business or customer information.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege authenticated account on the WooCommerce site.

Key dates

06Disclosure timeline

June 9, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE