CVE · Medium

CVE-2024-10486 — Google for WooCommerce [google-listings-and-ads] < 2.8.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-10486 Google for WooCommerce [google-listings-and-ads] < 2.8.7 Missing Authorization Medium 5.3 < 2.8.7 2.8.7 2024-11-18

CVE-2024-10486

The Google for WooCommerce plugin before version 2.8.7 contains an information disclosure vulnerability stemming from an unprotected print_php_information.php file that any visitor can access. Attackers without authentication can leverage this exposure to gather details about the web server and PHP setup, information that could facilitate further exploitation. The flaw affects all installations running version 2.8.6 and earlier.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.