Sensitive Information Exposure in WP Simple Shopping Cart Plugin
CVE-2023-1431
5.3MEDIUM
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 16 March 2023
What is CVE-2023-1431?
The WP Simple Shopping Cart plugin for WordPress has a vulnerability that allows unauthenticated attackers to access sensitive shopping cart data stored in a publicly accessible directory. This exposure affects versions up to 4.6.3 and could lead to unauthorized disclosure of personal information such as names, email addresses, and IP addresses, which are meant to be kept confidential within the administrative interface.
Affected Version(s)
WordPress Simple Shopping Cart 4.6.3