Impact
The vulnerability in the Shipmondo WooCommerce plugin allows an authenticated WordPress user to retrieve sensitive data that should be protected. The flaw is based on the improper handling of options, classified under CWE‑201, resulting in an arbitrary exposure of information that could contain user credentials, shipping details, or payment data. An attacker who can log into the WordPress admin panel could exploit this weakness to download the hidden options, compromising confidentiality and potentially impacting customer privacy.
Affected Systems
Shipmondo – A complete shipping solution for WooCommerce plugin version 5.0.3 and earlier are affected. Any WordPress installation that has this plugin installed without updating past 5.0.3 is at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1% shows a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, but because it requires authenticated access to the WordPress backend, it is still a concern for sites that have weak admin passwords or shared credentials. The attack vector is inferred to be a log‑in admin session, as the plugin’s option retrieval function is exposed only when the user has proper permissions.
OpenCVE Enrichment
EUVD