Arshid WooCommerce Quick View Missing Authorization Vulnerability Allowing Sensitive Data Exposure

Vulnerability

A missing authorization vulnerability in the Arshid WooCommerce Quick View plugin, affecting versions through 1.1.1, allows exploitation of improperly configured access control. This vulnerability could lead to unauthorized exposure of sensitive data that regular users typically cannot access.

Impact

Exploitation of this vulnerability could result in unauthorized access to sensitive information, potentially allowing for further exploitation of other weaknesses within the system.

Remediation

Users of the WooCommerce Quick View plugin should update to version 1.1.3 or later to address this vulnerability. Patchstack users can enable auto-update for vulnerable plugins.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.