Vulnerability Description
Information exposure vulnerability in the MRW plugin, in its 5.4.3 version, affecting the "mrw_log" functionality. This vulnerability could allow a remote attacker to obtain other customers' order information and access sensitive information such as name and phone number. This vulnerability also allows an attacker to create or overwrite shipping labels.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://www.incibe.es/en/incibe-cert/notices/aviso/information-exposure-vulnerab
- https://www.incibe.es/en/incibe-cert/notices/aviso/information-exposure-vulnerab
FAQ
What is CVE-2024-6506?
CVE-2024-6506 is a vulnerability with a CVSS score of 8.2 (HIGH). Information exposure vulnerability in the MRW plugin, in its 5.4.3 version, affecting the "mrw_log" functionality. This vulnerability could allow a remote attacker to obtain other customers' order inf...
How severe is CVE-2024-6506?
CVE-2024-6506 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-6506?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.