CVE-2024-13623

CVSS 3.1 Score 5.9 of 10 (medium)

Details

Published Jan 31, 2025
CWE ID 200

Summary

CVE-2024-13623 is a Sensitive Information Exposure vulnerability affecting the Order Export plugin for WooCommerce on WordPress. Unauthenticated attackers can exploit this vulnerability in all versions up to 3.24 by accessing the 'uploads' directory, where sensitive data from exported order information is stored insecurely. The vulnerability only exists when 'Order data storage' is set to 'WordPress posts storage (legacy)', and it cannot be exploited when the default 'High-performance order storage' option is enabled. This issue can result in the exposure of valuable order information, posing a significant risk to e-commerce sites using the affected plugin.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share