← Volver al buscador de CVEs

CVE-2026-7558

Age Verification & Identity Verification by Token of Trust

Descripción

The Age Verification & Identity Verification by Token of Trust plugin for WordPress is vulnerable to unauthorized access in all versions up to and including 4.0.2. This is due to the handle_export_table() function being registered on the WordPress -init- hook, which fires for all requests, including those from unauthenticated visitors, without any capability check. This makes it possible for unauthenticated attackers to download a CSV file containing sensitive WooCommerce donation data, including order dates, order IDs, charitable donation amounts, and admin-only order edit URLs, simply by visiting any page on the site with the -tot_export_table- GET parameter set to a numeric value (0–3).

CVSS 5.3EPSS 0.262%Riesgo 0.54
Ver fuente
Publicación
2026-07-09 08:16:49
Versiones afectadas
<=4.0.2
Tipo
Aplicación web
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N