Sensitive Data Exposure in WooCommerce Plugin by WordPress
CVE-2024-13641
7.5HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 14 February 2025
What is CVE-2024-13641?
The Return Refund and Exchange For WooCommerce plugin, compatible with WordPress, exposes sensitive information due to improper handling of file permissions. This vulnerability affects all versions up to and including 4.4.5, allowing unauthenticated attackers to access and extract sensitive data stored in the /wp-content/attachment directory. This includes potentially sensitive file attachments related to order refunds, making it crucial for users to update their plugin to ensure data security.
Affected Version(s)
Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Features * <= 4.4.5