What the vulnerability does
01Description
Missing Authorization vulnerability in WPExperts Wholesale For WooCommerce.This issue affects Wholesale For WooCommerce: from n/a through 2.3.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in WPExperts Wholesale For WooCommerce.This issue affects Wholesale For WooCommerce: from n/a through 2.3.0.
Explanation of Vulnerability in Simple Terms
Wholesale For WooCommerce versions up to 2.3.0 expose sensitive information that can be accessed over the network without authentication. An attacker can read data that should be restricted, such as pricing, customer details, or wholesale terms. No user interaction or special privileges are required. Update to a version newer than 2.3.0 to resolve this issue.
What an attacker can do
Read sensitive information like pricing, customer data, or wholesale terms without logging in.
Potential impact on your site
Competitors or malicious actors can view confidential wholesale pricing and customer information.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities