What the vulnerability does
01Description
Contributor Insecure Direct Object References (IDOR) in Product Slider for WooCommerce <= 1.13.62 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Contributor Insecure Direct Object References (IDOR) in Product Slider for WooCommerce <= 1.13.62 versions.
Explanation of Vulnerability in Simple Terms
Product Slider for WooCommerce versions up to 1.13.62 contain an authorization flaw that allows authenticated users with low privileges to read sensitive data they should not access. The vulnerability requires a valid user account but no special interaction. Site administrators should update to a version newer than 1.13.62 to prevent unauthorized information disclosure.
What an attacker can do
Read sensitive data from the site that should be restricted to higher-privilege users.
Potential impact on your site
Authenticated users can access confidential information beyond their permission level, risking data exposure.
Conditions required to exploit
Attacker must have a valid low-privilege user account on the site.
Key dates
External resources
Related vulnerabilities