← Späť na vyhľadávanie CVE

CVE-2026-7558

Age Verification & Identity Verification by Token of Trust

Popis

The Age Verification & Identity Verification by Token of Trust plugin for WordPress is vulnerable to unauthorized access in all versions up to and including 4.0.2. This is due to the handle_export_table() function being registered on the WordPress -init- hook, which fires for all requests, including those from unauthenticated visitors, without any capability check. This makes it possible for unauthenticated attackers to download a CSV file containing sensitive WooCommerce donation data, including order dates, order IDs, charitable donation amounts, and admin-only order edit URLs, simply by visiting any page on the site with the -tot_export_table- GET parameter set to a numeric value (0–3).

CVSS 5.3EPSS 0.262%Riziko 0.54
Zobraziť zdroj
Zverejnené
2026-07-09 08:16:49
Dotknuté verzie
<=4.0.2
Typ
Webová aplikácia
Vektor
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N