WordPress Email Marketing for WooCommerce by Omnisend Plugin <= 1.13.8 is vulnerable to Sensitive Data Exposure
CVE-2023-47244
7.5HIGH
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 23 November 2023
Summary
A vulnerability has been identified in Omnisend Email Marketing for WooCommerce, where sensitive information may be exposed to unauthorized users. This impacts all versions from n/a through 1.13.8, potentially allowing malicious actors to gain access to sensitive data. Users of the affected plugin are advised to take immediate action to safeguard their information by updating to the latest version.
Affected Version(s)
Email Marketing for WooCommerce by Omnisend <= 1.13.8
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Mika (Patchstack Alliance)