CVE-2023-6897: EAN for WooCommerce <= 4.9.2 - Insecure Direct Object Reference to Sensitve Information Exposure via Shortcode
The EAN for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.9.2 via the the 'algwceanproductmeta' shortcode due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with contributor-level access and above, to expose potentially sensitive post metadata.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-6897?
CVE-2023-6897 has been classified as a medium severity vulnerability due to the potential for authenticated attackers to exploit it.
How do I fix CVE-2023-6897?
To fix CVE-2023-6897, update the EAN for WooCommerce plugin to version 4.9.3 or later.
Who is affected by CVE-2023-6897?
CVE-2023-6897 affects all installations of the EAN for WooCommerce plugin up to and including version 4.9.2.
What type of vulnerability is CVE-2023-6897?
CVE-2023-6897 is categorized as an Insecure Direct Object Reference vulnerability.
What systems are impacted by CVE-2023-6897?
CVE-2023-6897 impacts WordPress sites that use the EAN for WooCommerce plugin.