Sensitive Data Exposure in WooCommerce Plugin by WordPress
CVE-2024-13641
7.5HIGH
Key Information:
- Vendor
- WordPress
- Vendor
- CVE Published:
- 14 February 2025
Summary
The Return Refund and Exchange For WooCommerce plugin, compatible with WordPress, exposes sensitive information due to improper handling of file permissions. This vulnerability affects all versions up to and including 4.4.5, allowing unauthenticated attackers to access and extract sensitive data stored in the /wp-content/attachment directory. This includes potentially sensitive file attachments related to order refunds, making it crucial for users to update their plugin to ensure data security.
Affected Version(s)
Return Refund and Exchange For WooCommerce – Return Management System, RMA Exchange, Wallet And Cancel Order Features * <= 4.4.5
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Tim Coen