Beta

Report

Booster Plus for WooCommerce < 7.1.3 is vulnerable to Authenticated Arbitrary WordPress Option Disclosure Vulnerability

Subscriber
Published
2024-01-04

The Booster Plus for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on an unknown function in all versions up to 7.1.3 (exclusive). This makes it possible for authenticated attackers, with subscriber-level access and above, to retrieve arbitrary WordPress option values.

CVSS

Score:6.5

Severity:Medium

Version:< 7.1.3

There is a patch available in v7.1.3 and we strongly recommend you update to this version as soon as possible.