Sensitive Information Exposure Vulnerability in Melhor Envio Plugin for WordPress
CVE-2024-13820
5.3MEDIUM
What is CVE-2024-13820?
The Melhor Envio plugin for WordPress is susceptible to sensitive information exposure due to a misconfiguration in the 'run' function, where a hardcoded hash is utilized. This flaw permits unauthenticated attackers to gain access to critical data elements, including environment details, plugin tokens, shipping settings, and certain vendor-related information. This vulnerability poses significant risks for users relying on the plugin, as it could lead to unauthorized access and data breaches.
Affected Version(s)
Melhor Envio 0 <= 2.15.11