The Mollie Payments for WooCommerce plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 7.7.0. This is due to the error reporting being enabled by default in multiple plugin files. This makes it possible for unauthenticated attackers to obtain the full path to instances, which they may be able to use in combination with other vulnerabilities or to simplify reconnaissance work. On its own, this information is of very limited use.
Metrics
Affected Vendors & Products
References
History
Wed, 28 Aug 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Mollie
Mollie mollie Payments For Woocommerce |
|
CPEs | cpe:2.3:a:mollie:mollie_payments_for_woocommerce:*:*:*:*:*:wordpress:*:* | |
Vendors & Products |
Mollie
Mollie mollie Payments For Woocommerce |
|
Metrics |
ssvc
|
Wed, 28 Aug 2024 03:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Mollie Payments for WooCommerce plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 7.7.0. This is due to the error reporting being enabled by default in multiple plugin files. This makes it possible for unauthenticated attackers to obtain the full path to instances, which they may be able to use in combination with other vulnerabilities or to simplify reconnaissance work. On its own, this information is of very limited use. | |
Title | Mollie Payments for WooCommerce <= 7.7.0 - Unauthenticated Full Path Disclosure | |
Weaknesses | CWE-200 | |
References |
|
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Wordfence
Published: 2024-08-28T03:27:28.062Z
Updated: 2024-08-28T13:42:06.740Z
Reserved: 2024-07-02T10:16:17.071Z
Link: CVE-2024-6448
Vulnrichment
Updated: 2024-08-28T13:41:45.821Z
NVD
Status : Awaiting Analysis
Published: 2024-08-28T04:15:11.320
Modified: 2024-08-28T12:57:27.610
Link: CVE-2024-6448
Redhat
No data.