What the vulnerability does
01Description
Unauthenticated Sensitive Data Exposure in WooCommerce Appointments <= 5.3.8 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Unauthenticated Sensitive Data Exposure in WooCommerce Appointments <= 5.3.8 versions.
Explanation of Vulnerability in Simple Terms
WooCommerce Appointments versions up to 5.3.8 expose sensitive system information to unauthenticated attackers over the network. An attacker can retrieve details about the site's configuration and internal structure without needing to log in or interact with a user. This information disclosure could aid further attacks against the site.
What an attacker can do
Read sensitive system information about the site's configuration and internal structure.
Potential impact on your site
Attackers can gather reconnaissance data about your site's setup, potentially enabling follow-up attacks.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities