CVE · High

CVE-2020-12070 — Advanced Woo Search – Product Search for WooCommerce [advanced-woo-search] < 2.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2020-12070 Advanced Woo Search – Product Search for WooCommerce [advanced-woo-search] < 2.0 Exposure of Sensitive Information to an Unauthorized Actor High 7.5 < 2.0 2.0 2020-04-22

CVE-2020-12070

The Advanced Woo Search plugin up to version 1.99 contains a sensitive information disclosure flaw that exposes data through ajax search requests. An attacker can leverage the sql parameter sent to includes/class-aws-search.php to retrieve sensitive information. This vulnerability affects all versions prior to 2.0 of the plugin.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.