Unauthorized Access to Sensitive Information
CVE-2024-43258
7.5HIGH
Summary
The vulnerability pertains to the Store Locator Plus plugin, where sensitive information can be exposed to unauthorized actors. This issue impacts versions of the plugin from its initial release through 2311.17.01, raising significant concerns around the security of user data. Proper access controls are essential to prevent unauthorized access and ensure data integrity within applications utilizing this plugin. Implementing security measures is critical to safeguarding sensitive user information against potential breaches.
Affected Version(s)
Store Locator Plus <= 2311.17.01
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Credit
Peng Zhou (Patchstack Alliance)