First published: Thu May 09 2024(Updated: )
The ShopLentor (formerly WooLentor) plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the purchased_new_products function in all versions up to, and including, 2.8.7. This makes it possible for unauthenticated attackers to view all products purchased in the past week, along with the users that purchased them.
Credit: security@wordfence.com
Affected Software | Affected Version | How to fix |
---|---|---|
ShopLentor | <=2.8.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-6327 is considered a high severity vulnerability due to its potential for unauthorized data access.
To fix CVE-2023-6327, update the ShopLentor plugin to version 2.8.8 or later.
CVE-2023-6327 affects all versions of the ShopLentor plugin for WordPress up to and including 2.8.7.
CVE-2023-6327 is a vulnerability that allows unauthorized access to data due to a missing capability check.
Yes, unauthenticated attackers can exploit CVE-2023-6327 to view sensitive data.