Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

BigCommerce <= 5.0.7 - Unauthenticated Sensitive Information Exposure #455

Open
2gen opened this issue Feb 1, 2024 · 0 comments
Open

BigCommerce <= 5.0.7 - Unauthenticated Sensitive Information Exposure #455

2gen opened this issue Feb 1, 2024 · 0 comments

Comments

@2gen
Copy link

2gen commented Feb 1, 2024

https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/bigcommerce/bigcommerce-506-unauthenticated-sensitive-information-exposure

The BigCommerce For WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.0.7. This makes it possible for unauthenticated attackers to extract sensitive data.

Anyone know what sensitive information is currently exposed?

Also any indication when this will be patched?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

No branches or pull requests

1 participant