What the vulnerability does
01Description
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Booster Booster Plus for WooCommerce.This issue affects Booster Plus for WooCommerce: from n/a before 7.1.2.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Booster Booster Plus for WooCommerce.This issue affects Booster Plus for WooCommerce: from n/a before 7.1.2.
Explanation of Vulnerability in Simple Terms
Booster Plus for WooCommerce versions before 7.1.2 expose sensitive information to authenticated users. A logged-in user with low privileges can read data they should not have access to through the plugin's functionality. The vulnerability does not allow data modification or system unavailability. Update to version 7.1.2 or later to resolve this issue.
What an attacker can do
Read sensitive information accessible only to higher-privileged users or other site users.
Potential impact on your site
Customer data, order details, or other sensitive information may be visible to low-privilege users who should not access it.
Conditions required to exploit
Attacker must be logged in to the site with a low-privilege account (e.g., subscriber or customer).
Key dates
External resources
Related vulnerabilities