Impact
The Geliver Akıllı Kargo Pazaryeri WordPress plugin writes a log file that is publicly accessible. When unauthenticated users trigger requests, the log file records the site's carrier integration key and customer details from processed orders. An attacker who can read this file directly obtains the integration key, which can then be used to alter WooCommerce order statuses, potentially enabling fraudulent or misleading changes to order data. The main consequence is a loss of confidentiality for sensitive keys and customer information, and a disruption of order integrity, which could undermine customer trust and financial accuracy.
Affected Systems
This vulnerability affects the Geliver Akıllı Kargo Pazaryeri WordPress plugin versions earlier than 3.1.1. The plugin is used within WordPress sites that also host WooCommerce for e‑commerce operations. Any site that has installed one of these vulnerable plugin versions and has the plugin's log directory exposed in the web root is impacted.
Risk and Exploitability
The vulnerability is exploitable through unauthenticated HTTP access to a predictable log file location inside the web‑accessible directory of the plugin. An attacker needs only to request the file URL; no credential or additional privilege is required. The vulnerability has a CVSS score of 6.5, indicating moderate severity, and the impact is high because the disclosed data includes an API key that can be used to modify order statuses. Exploitation probability is unknown due to lack of EPSS data, but the fact that the file is world‑readable makes exploitation straightforward. The vulnerability is not listed in CISA’s KEV catalog; nonetheless its potential to disrupt e‑commerce processes warrants prompt remediation.
OpenCVE Enrichment