{“error”:0,”message”:null,”data”:{“name”:”Google for WooCommerce”,”plugin”:”google-listings-and-ads”,”link”:”https:\/\/wordpress.org\/plugins\/google-listings-and-ads\/”,”latest”:”1753175640″,”closed”:0,”vulnerability”:[{“uuid”:”aa40f51f703c5ad24d275f0205e7880313cf07a797141f84cfa7cc18f197f077″,”name”:”Google for WooCommerce [google-listings-and-ads] < 2.8.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.8.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-10486","name":"CVE-2024-10486","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-10486","description":"[en] The Google for WooCommerce plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 2.8.6. This is due to publicly accessible print_php_information.php file. This makes it possible for unauthenticated attackers to retrieve information about Webserver and PHP configuration, which can be used to aid other attacks.","date":"2024-11-18"},{"id":"818796bad759df2cb1080b635b8088fa90c20dd4","name":"Google for WooCommerce <= 2.8.6 - Information Disclosure via Publicly Accessible PHP Info File","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/google-listings-and-ads\/google-for-woocommerce-286-information-disclosure-via-publicly-accessible-php-info-file","description":"The Google for WooCommerce plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 2.8.6. This is due to publicly accessible print_php_information.php file. This makes it possible for unauthenticated attackers to retrieve information about Webserver and PHP configuration, which can be used to aid other attacks.","date":"2024-11-18"},{"id":"b0183abb45b28ddfb90bcc91f920c54cefa582d0","name":"WordPress Google for WooCommerce Plugin <= 2.8.6 is vulnerable to Sensitive Data Exposure","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/google-listings-and-ads\/vulnerability\/wordpress-google-for-woocommerce-plugin-2-8-6-information-disclosure-via-publicly-accessible-php-info-file-vulnerability","description":"
WordPress Google for WooCommerce Plugin <= 2.8.6 is vulnerable to Sensitive Data Exposure<\/p>
Software: Google for WooCommerce<\/p>
Link: https:\/\/wordpress.org\/plugins\/google-listings-and-ads\/#developers<\/p>
Affected Version <= 2.8.6<\/p>
Fixed in version 2.8.7 <\/p>“,”date”:”2024-11-18″}],”impact”:{“cvss”:{“version”:”3.1″,”vector”:”CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N”,”av”:”n”,”ac”:”l”,”pr”:”n”,”ui”:”n”,”s”:”u”,”c”:”l”,”i”:”n”,”a”:”n”,”score”:”5.3″,”severity”:”m”,”exploitable”:”0.0″,”impact”:”0.0″},”cwe”:[{“cwe”:”CWE-862″,”name”:”Missing Authorization”,”description”:”The product does not perform an authorization check when an actor attempts to access a resource or perform an action.”}]}}]},”updated”:”1750132260″}