CVE-2024-13525: Customer Email Verification for WooCommerce <= 2.9.4 - Authenticated (Contributor+) Sensitive Information Exposure
The Customer Email Verification for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.4 via Shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including emails as well as hashed passwords of any user.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13525?
CVE-2024-13525 has been identified as a critical vulnerability that allows authenticated attackers to access sensitive information.
How do I fix CVE-2024-13525?
To fix CVE-2024-13525, update the Customer Email Verification for WooCommerce plugin to version 2.9.5 or later.
Who is affected by CVE-2024-13525?
CVE-2024-13525 affects users of the Customer Email Verification for WooCommerce plugin up to version 2.9.4.
What types of sensitive information are exposed in CVE-2024-13525?
CVE-2024-13525 allows authenticated attackers to extract sensitive customer data, potentially including email addresses and personal identifiers.
What versions are impacted by CVE-2024-13525?
CVE-2024-13525 impacts all versions of the Customer Email Verification for WooCommerce plugin up to and including version 2.9.4.