CVE-2021-25002
Last modified
CVE-2021-25002 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. The Tipsacarrier WordPress plugin before 1.5.0.5 does not have any authorisation check in place some functions, which could allow unauthenticated users to access Orders data which could be used to retrieve the client full address, name and phone via tracking URL. EPSS estimates a 1.44% chance of exploitation in the next 30 days.
Description
The Tipsacarrier WordPress plugin before 1.5.0.5 does not have any authorisation check in place some functions, which could allow unauthenticated users to access Orders data which could be used to retrieve the client full address, name and phone via tracking URL
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tipsacarrier Project | Tipsacarrier | < 1.5.0.5 |
References
- https://wpscan.com/vulnerability/b14f476e-3124-4cbf-91b4-ae53c4dabd7cExploit, Third Party Advisory
- https://wpscan.com/vulnerability/b14f476e-3124-4cbf-91b4-ae53c4dabd7cExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-25002?
How severe is CVE-2021-25002?
How do I fix CVE-2021-25002?
Are you affected by CVE-2021-25002?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
