CVE-2023-40327

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Jan 2, 2025
CWE ID 862

Summary

CVE-2023-40327 is a critical vulnerability affecting the Putler Connector for WooCommerce, with versions from n/a to 2.12.0 being impacted. This issue involves a missing authorization check, allowing unauthorized access to sensitive data. Attackers can exploit this flaw to gain unauthorized access to customer information, including orders and payment details, potentially leading to financial loss and privacy breaches for affected WooCommerce stores. Merchants using the Putler Connector for WooCommerce are urged to upgrade to the latest, secure version as soon as possible to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share