Impact
Unauthenticated users can read confidential data stored by the Kit (formerly ConvertKit) for WooCommerce plugin when it runs on a WordPress site. The flaw, classified as CWE‑497, results from missing authentication checks before data is returned and allows attackers to retrieve personal information, transaction details, or other sensitive content without possessing legitimate credentials.
Affected Systems
WordPress sites that use the Nathanbarry:Kit (formerly ConvertKit) for WooCommerce plugin version 2.1.5 or older are affected. Any WooCommerce installation that includes this plugin can expose user data through the plugin’s exposed interfaces or internal data retrieval mechanisms.
Risk and Exploitability
The CVSS score of 5.3 places the issue in the moderate category. The EPSS score of less than 1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit this flaw by sending unauthenticated HTTP requests to the plugin’s data endpoints, retrieving sensitive data without any authentication or privileged access. No evidence of widespread active exploitation is known at the time of analysis. The likely attack vector involves sending unauthenticated HTTP requests to plugin endpoints that expose sensitive data, inferred from the described behaviour.
OpenCVE Enrichment