WordPress Plugin Vulnerabilities

Sprout Invoices < 20.5.4 - Sensitive Information Exposure

Description

The plugin is vulnerable to Sensitive Information Exposure in all versions up to 20.5.4 (exclusive) via the system_health_check function. This makes it possible for authenticated attackers with subscriber access and above to extract sensitive data including system configuration information.

Affects Plugins

Fixed in 20.5.4

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE

Miscellaneous

Timeline

Publicly Published
2023-11-13 (about 2 years ago)
Added
2024-01-17 (about 2 years ago)
Last Updated
2024-01-17 (about 2 years ago)

Other