← Zurück zur CVE-Suche

CVE-2026-7558

Age Verification & Identity Verification by Token of Trust

Beschreibung

The Age Verification & Identity Verification by Token of Trust plugin for WordPress is vulnerable to unauthorized access in all versions up to and including 4.0.2. This is due to the handle_export_table() function being registered on the WordPress -init- hook, which fires for all requests, including those from unauthenticated visitors, without any capability check. This makes it possible for unauthenticated attackers to download a CSV file containing sensitive WooCommerce donation data, including order dates, order IDs, charitable donation amounts, and admin-only order edit URLs, simply by visiting any page on the site with the -tot_export_table- GET parameter set to a numeric value (0–3).

CVSS 5.3EPSS 0.262%Risiko 0.54
Quelle öffnen
Veröffentlicht
2026-07-09 08:16:49
Betroffene Versionen
<=4.0.2
Typ
Webanwendung
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N