PT-2025-48252 · WordPress · Quick View For Woocommerce

·

CVE-2025-12584

·

Publicado

2025-11-27

·

Atualizado

2025-11-27

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Quick View for WooCommerce plugin for WordPress versions up to and including 2.2.17
Description The Quick View for WooCommerce plugin for WordPress is susceptible to information disclosure. This issue affects versions prior to and including 2.2.17. An unauthenticated attacker can potentially extract data from private products that they are not authorized to access. This is due to insufficient restrictions on which products can be included via the wqv popup content API endpoint.
Recommendations Update the Quick View for WooCommerce plugin to a version later than 2.2.17.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-12584

Produtos afetados

Quick View For Woocommerce