Sensitive Data Exposure in WooCommerce Plugin by WordPress
CVE-2024-13641

5.9MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
14 February 2025

What is CVE-2024-13641?

The Return Refund and Exchange For WooCommerce plugin, compatible with WordPress, exposes sensitive information due to improper handling of file permissions. This vulnerability affects all versions up to and including 4.4.5, allowing unauthenticated attackers to access and extract sensitive data stored in the /wp-content/attachment directory. This includes potentially sensitive file attachments related to order refunds, making it crucial for users to update their plugin to ensure data security.

Affected Version(s)

Return Refund and Exchange For WooCommerce 0 <= 4.4.5

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tim Coen
.