What the vulnerability does
01Description
Insertion of Sensitive Information Into Sent Data vulnerability in Greys Korea for WooCommerce korea-for-woocommerce allows Retrieve Embedded Sensitive Data.This issue affects Korea for WooCommerce: from n/a through <= 1.1.11.
Explanation of Vulnerability in Simple Terms
02Summary
Korea for WooCommerce versions up to 1.1.11 contain an information disclosure vulnerability. An attacker with low-level site access can read sensitive data that should be restricted. The vulnerability does not require user interaction and affects confidentiality only. Update to a version newer than 1.1.11.
What an attacker can do
03Attacker Capabilities
Read sensitive data restricted to higher-privilege users.
Potential impact on your site
04Site Impact
Customer or user data may be exposed to low-privilege attackers; review access logs and audit data exposure.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege account on the site (e.g., subscriber or customer role).
Key dates
06Disclosure timeline
February 3, 2025
CVE published
May 11, 2026
Record updated