melhorenvio/wp-melhorenvio-v2

melhorenvio/wp-melhorenvio-v2

Releases50
Frequency1 month 1 week
Last Release
Stars14

CVE History

CVEPublishedCVSS v3CVSS v2
5.3 MEDIUM

The Melhor Envio plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.15.11 via the 'run' function, which uses a hardcoded hash. This makes it possible for unauthenticated attackers to extract sensitive data including environment information, plugin tokens, shipping configurations, and limited vendor information.