First published: Mon Mar 07 2022(Updated: )
The CorreosExpress WordPress plugin through 2.6.0 generates log files which are publicly accessible, and contain sensitive information such as sender/receiver names, phone numbers, physical and email addresses
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Prestashop Correos Express | <=2.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25009 is classified as a high severity vulnerability due to the exposure of sensitive personal information.
To fix CVE-2021-25009, update the CorreosExpress plugin to a version above 2.6.0.
CVE-2021-25009 exposes sensitive information including sender and receiver names, phone numbers, email addresses, and physical addresses.
CVE-2021-25009 affects all versions of the CorreosExpress plugin up to and including 2.6.0.
CVE-2021-25009 is a remote vulnerability as it allows public access to sensitive log files.