What the vulnerability does
01Description
Missing Authorization vulnerability in WPFactory Products, Order & Customers Export for WooCommerce.This issue affects Products, Order & Customers Export for WooCommerce: from n/a through 2.0.8.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Missing Authorization vulnerability in WPFactory Products, Order & Customers Export for WooCommerce.This issue affects Products, Order & Customers Export for WooCommerce: from n/a through 2.0.8.
Explanation of Vulnerability in Simple Terms
The Products, Order & Customers Export for WooCommerce plugin through version 2.0.8 does not properly check user permissions before allowing access to export functionality. An unauthenticated attacker can read sensitive customer and order data by directly accessing the export feature without logging in. This exposes names, email addresses, purchase history, and other business-critical information.
What an attacker can do
Read exported customer names, email addresses, order details, and other sensitive WooCommerce data without logging in.
Potential impact on your site
Customer and order data can be downloaded by anyone, exposing privacy and creating compliance risk.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities