5.3
CVE-2024-6448
- EPSS 0.46%
- Veröffentlicht 28.08.2024 04:15:11
- Zuletzt bearbeitet 09.07.2025 14:42:18
- Quelle security@wordfence.com
- CVE-Watchlists
- Unerledigt
Mollie Payments for WooCommerce <= 7.7.0 - Unauthenticated Full Path Disclosure
The Mollie Payments for WooCommerce plugin for WordPress is vulnerable to information exposure in all versions up to, and including, 7.7.0. This is due to the error reporting being enabled by default in multiple plugin files. This makes it possible for unauthenticated attackers to obtain the full path to instances, which they may be able to use in combination with other vulnerabilities or to simplify reconnaissance work. On its own, this information is of very limited use.
Mögliche Gegenmaßnahme
Mollie Payments for WooCommerce: Update to version 7.8.0, or a newer patched version
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Mollie Payments for WooCommerce
Version
*-7.7.0
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mollie ≫ Mollie Payments For Woocommerce SwPlatformwordpress Version < 7.8.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.46% | 0.636 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@wordfence.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.