What the vulnerability does
01Description
Insertion of Sensitive Information into Log File vulnerability in AdTribes.Io Product Feed PRO for WooCommerce.This issue affects Product Feed PRO for WooCommerce: from n/a through 13.3.1.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Insertion of Sensitive Information into Log File vulnerability in AdTribes.Io Product Feed PRO for WooCommerce.This issue affects Product Feed PRO for WooCommerce: from n/a through 13.3.1.
Explanation of Vulnerability in Simple Terms
Product Feed PRO for WooCommerce versions up to 13.3.1 expose sensitive information through improper logging or data exposure. An attacker on the network can read confidential data without authentication or user interaction. The vulnerability affects the plugin's data handling, potentially exposing customer or configuration details. Update to a version newer than 13.3.1 to remediate.
What an attacker can do
Read sensitive information from the plugin without authentication.
Potential impact on your site
Customer data, API keys, or configuration details may be exposed to unauthenticated attackers.
Conditions required to exploit
Network access to the affected WooCommerce site; no authentication required.
Key dates
External resources
Related vulnerabilities