Melhor Envio WordPress Plugin Sensitive Information Exposure Vulnerability

Vulnerability

A vulnerability allowing sensitive information exposure has been identified in the Melhor Envio plugin for WordPress, affecting all versions through 2.15.11. The issue arises in the 'run' function, which contains a hardcoded hash. This vulnerability enables unauthenticated attackers to access sensitive data such as environment details, plugin tokens, shipping configurations, and limited vendor information.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive information, including environment data, plugin tokens, shipping settings, and some vendor details.

Reproduction

The vulnerability can be reproduced by sending a request to the 'run' function of the Melhor Envio plugin with a hash parameter. The request will be processed if the hash matches the hardcoded value, bypassing authorization checks. This allows for the extraction of sensitive information.

Remediation

Users are advised to update the Melhor Envio WordPress plugin to version 2.15.12 or later.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.4
remediation
7.7
relevance
0.0
threat
4.8
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.