Описание
The Event Booking Manager for WooCommerce WordPress plugin before 5.6.0 does not restrict who can view its stored payment gateway configuration, allowing users with Contributor-level access and above to read the site's PayPal and Stripe credentials, including their secret keys.
EPSS
Процентиль: 13%
0.00222
Низкий
4.9 Medium
CVSS3
Дефекты
CWE-284
Связанные уязвимости
CVSS3: 4.9
github
2 дня назад
The Event Booking Manager for WooCommerce WordPress plugin before 5.6.0 does not restrict who can view its stored payment gateway configuration, allowing users with Contributor-level access and above to read the site's PayPal and Stripe credentials, including their secret keys.
EPSS
Процентиль: 13%
0.00222
Низкий
4.9 Medium
CVSS3
Дефекты
CWE-284