WordPress 的 WooCommerce “Order Export & Order Import” 插件在 2.7.8 及以下所有版本中存在敏感信息泄露漏洞,该漏洞可通过 函数触发。此漏洞使得未经身份验证的攻击者能够通过 HTTP 协议(无需任何认证)直接提取已导出的订单 CSV 文件,从而获取包含客户个人身份信息(PII)的数据,包括姓名、账单和配送地址、电子邮件地址、电话号码以及订单内容等。 当 目录下缺失 和 等防护文件时,该漏洞即可被利用。这种情况可能发生在任何卸载/重新安装周期、迁移、备份恢复或站
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| webtoffee | Order Export & Order Import for WooCommerce | 0 ~ 2.7.8 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet