What the vulnerability does
01Description
Subscriber Sensitive Data Exposure in ЮKassa для WooCommerce <= 2.16.1 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Subscriber Sensitive Data Exposure in ЮKassa для WooCommerce <= 2.16.1 versions.
Explanation of Vulnerability in Simple Terms
The YooMoney payment gateway plugin for WooCommerce (versions up to 2.16.1) exposes sensitive payment and customer data to authenticated users with low privileges. An attacker with a standard user account can read confidential information including transaction details and personal data. The vulnerability does not allow modification or deletion of data, but the information disclosure poses a significant privacy risk for site operators and their customers.
What an attacker can do
Read sensitive payment transaction data and customer information accessible through the plugin.
Potential impact on your site
Customer payment records and personal data may be exposed to unauthorized users with basic site access.
Conditions required to exploit
Attacker must have a low-privilege user account on the WooCommerce site; no user interaction required.
Key dates
External resources
Related vulnerabilities