WordPress SalesKing Plugin <= 1.6.15 is vulnerable to Sensitive Data Exposure
CVE-2024-22154
7.5HIGH
Summary
An exposure of sensitive information vulnerability has been identified in SNP Digital's SalesKing plugin, which affects versions up to 1.6.15. This vulnerability allows unauthorized actors to gain access to sensitive data that should remain confidential, posing significant risks to user privacy and data integrity. Organizations utilizing affected versions are urged to implement necessary security measures to mitigate potential breaches and protect their sensitive information.
Affected Version(s)
SalesKing <= 1.6.15
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dave Jong (Patchstack)