Impact
Insertion of Sensitive Information Into Sent Data allows attackers to retrieve embedded sensitive data from the WooCommerce Orders & Customers Exporter plugin. The vulnerability exposes confidential customer information by including it in the export output, constituting a confidentiality breach described by CWE‑201.
Affected Systems
The affected product is vanquish WooCommerce Orders & Customers Exporter plugin for WordPress. Versions from the earliest available release through 5.0 are vulnerable. Site admins who run any of these versions risk exposing customer order and customer data via the export function.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity impact, though the EPSS score of less than 1% suggests that exploitation is currently rare. The plugin is not listed in the CISA KEV catalog. Attackers would likely need remote access to the WordPress site or the ability to trigger the export action, which is typically available to authenticated administrators. Therefore, the primary attack vector is inferred to be authenticated remote access.
OpenCVE Enrichment
EUVD