Insufficient Restrictions in Sell-Downloads Plugin for WordPress
CVE-2015-9348
7.5HIGH
What is CVE-2015-9348?
The Sell-Downloads plugin for WordPress versions before 1.0.8 exhibits insufficient restrictions that allow attackers to perform brute-force guessing attacks on purchase IDs. This vulnerability can enable unauthorized users to access sensitive purchase information, risking the integrity and security of e-commerce transactions. To protect against this threat, it is crucial for users to update to the latest version of the plugin and implement additional security measures.