PT-2026-68393 · Peprodev · Woocommerce Receipt Uploader
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
PeproDev WooCommerce Receipt Uploader versions prior to 2.8.1
Description
An Insecure Direct Object Reference (IDOR) exists where the plugin fails to verify if a requested attachment belongs to the order associated with the provided access token. This allows unauthenticated attackers to forge a token and disclose image attachments, such as payment receipts uploaded by other customers.
Recommendations
Update PeproDev WooCommerce Receipt Uploader to version 2.8.1 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Woocommerce Receipt Uploader