Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4cx9-g5q6-23vf

Опубликовано: 31 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 3.7

Описание

The FluentCart A New Era of eCommerce WordPress plugin before 1.5.3 does not perform any authorization or ownership check before rendering customer order documents keyed on a sequential numeric identifier, allowing unauthenticated visitors to enumerate and disclose customer personal data (names, email addresses, billing and shipping postal addresses, and order details) across the store.

The FluentCart A New Era of eCommerce WordPress plugin before 1.5.3 does not perform any authorization or ownership check before rendering customer order documents keyed on a sequential numeric identifier, allowing unauthenticated visitors to enumerate and disclose customer personal data (names, email addresses, billing and shipping postal addresses, and order details) across the store.

EPSS

Процентиль: 6%
0.00162
Низкий

3.7 Low

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 3.7
nvd
около 2 месяцев назад

The FluentCart A New Era of eCommerce WordPress plugin before 1.5.3 does not perform any authorization or ownership check before rendering customer order documents keyed on a sequential numeric identifier, allowing unauthenticated visitors to enumerate and disclose customer personal data (names, email addresses, billing and shipping postal addresses, and order details) across the store.

EPSS

Процентиль: 6%
0.00162
Низкий

3.7 Low

CVSS3

Дефекты

CWE-639