Beta

Report

Ebook Store <= 5.775 is vulnerable to Broken Authentication vulnerability

Unauthenticated
Published
2023-04-18

The Ebook Store plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ebook_store_export_orders function in versions up to, and including, 5.775. This makes it possible for unauthenticated attackers to export order info.

CVSS

Score:7.5

Severity:High

Version: 5.775

There is a patch available in v5.78 and we strongly recommend you update to this version as soon as possible.