What the vulnerability does
01Description
Subscriber Sensitive Data Exposure in Print Barcode Labels for your WooCommerce products/orders <= 4.0.0 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Subscriber Sensitive Data Exposure in Print Barcode Labels for your WooCommerce products/orders <= 4.0.0 versions.
Explanation of Vulnerability in Simple Terms
The Print Barcode Labels plugin for WooCommerce through version 4.0.0 exposes sensitive information in outgoing data. An authenticated user with low privileges can trigger the plugin to leak confidential details in network communications. The vulnerability does not allow modification or deletion of data, but the information disclosure poses a risk to order and customer privacy.
What an attacker can do
Read sensitive information sent by the plugin in network traffic or responses.
Potential impact on your site
Customer and order data may be exposed to authenticated users who should not have access to it.
Conditions required to exploit
Attacker must have a low-privilege WooCommerce user account (e.g., customer or shop manager).
Key dates
External resources
Related vulnerabilities