What the vulnerability does
01Description
Unauthenticated Sensitive Data Exposure in Signature Add-On for WooCommerce <= 2.0 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Unauthenticated Sensitive Data Exposure in Signature Add-On for WooCommerce <= 2.0 versions.
Explanation of Vulnerability in Simple Terms
The Signature Add-On for WooCommerce through version 2.0 exposes sensitive data without proper access controls. An attacker on the network can read confidential information directly without authentication or user interaction. This affects all installations of the plugin up to and including version 2.0.
What an attacker can do
Read sensitive data from the plugin without logging in or user interaction.
Potential impact on your site
Customer or business data stored by the plugin may be exposed to anyone on the internet.
Conditions required to exploit
Network access only; no authentication or user action required.
Key dates
External resources
Related vulnerabilities