The Product Table for WooCommerce by CodeAstrology (wooproducttable.com) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.1 via the var_dump_table parameter. This makes it possible for unauthenticated attackers var data.
History

Tue, 26 Nov 2024 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Codeastrology
Codeastrology woo Product Table
CPEs cpe:2.3:a:codeastrology:woo_product_table:*:*:*:*:*:*:*:*
Vendors & Products Codeastrology
Codeastrology woo Product Table
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 23 Nov 2024 03:45:00 +0000

Type Values Removed Values Added
Description The Product Table for WooCommerce by CodeAstrology (wooproducttable.com) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.1 via the var_dump_table parameter. This makes it possible for unauthenticated attackers var data.
Title Product Table for WooCommerce by CodeAstrology (wooproducttable.com) <= 3.5.1 - Information Exposure
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2024-11-23T03:25:51.400Z

Updated: 2024-11-26T19:39:46.843Z

Reserved: 2024-11-04T18:36:39.335Z

Link: CVE-2024-10813

cve-icon Vulnrichment

Updated: 2024-11-26T19:39:38.540Z

cve-icon NVD

Status : Received

Published: 2024-11-23T04:15:07.800

Modified: 2024-11-23T04:15:07.800

Link: CVE-2024-10813

cve-icon Redhat

No data.