Description

The Google for WooCommerce plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 2.8.6. This is due to publicly accessible print_php_information.php file. This makes it possible for unauthenticated attackers to retrieve information about Webserver and PHP configuration, which can be used to aid other attacks.

INFO

Published Date :

2024-11-18T21:31:09.032Z

Last Modified :

2026-04-08T16:57:37.812Z

Source :

Wordfence
AFFECTED PRODUCTS

The following products are affected by CVE-2024-10486 vulnerability.

Vendors Products
Automattic
  • Woocommerce

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact