CVE-2021-25009: CorreosExpress <= 2.6.0 - Sensitive Information Disclosure
Published Mar 7, 2022
·Updated
The CorreosExpress WordPress plugin through 2.6.0 generates log files which are publicly accessible, and contain sensitive information such as sender/receiver names, phone numbers, physical and email addresses
Affected Software
1 affected component
Correosexpress Project Correosexpress Wordpress<=2.6.0
Event History
Mar 7, 2022
CVE Published
via MITRE·08:16 AM
Data Sourced
via MITRE·08:16 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-25009?
CVE-2021-25009 is classified as a high severity vulnerability due to the exposure of sensitive personal information.
2
How do I fix CVE-2021-25009?
To fix CVE-2021-25009, update the CorreosExpress plugin to a version above 2.6.0.
3
What sensitive information is exposed in CVE-2021-25009?
CVE-2021-25009 exposes sensitive information including sender and receiver names, phone numbers, email addresses, and physical addresses.
4
Which versions of the CorreosExpress plugin are affected by CVE-2021-25009?
CVE-2021-25009 affects all versions of the CorreosExpress plugin up to and including 2.6.0.
5
Is CVE-2021-25009 a local or remote vulnerability?
CVE-2021-25009 is a remote vulnerability as it allows public access to sensitive log files.