WPFactory Advanced WooCommerce Product Sales Reporting Sensitive Data Exposure Vulnerability
Vulnerability
A vulnerability allowing the exposure of sensitive information has been identified in the WPFactory Advanced WooCommerce Product Sales Reporting plugin, specifically in versions through 4.1.2. This issue arises from the insertion of sensitive data into sent communications, which can be retrieved by unauthorized users.
Impact
Exploitation of this vulnerability could lead to unauthorized access to sensitive information that regular users cannot typically view, potentially allowing for further exploitation of other system weaknesses.
Remediation
Users of the WPFactory Advanced WooCommerce Product Sales Reporting plugin should update to version 4.1.3 or later to address this vulnerability. Patchstack users can enable auto-update for vulnerable plugins.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
