CVE Database /
CVE-2024-10486
CVE · Medium
CVE-2024-10486 — Google for WooCommerce [google-listings-and-ads] < 2.8.7
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-10486
|
Google for WooCommerce [google-listings-and-ads] < 2.8.7 |
Missing Authorization |
Medium
5.3
|
< 2.8.7
|
2.8.7 |
2024-11-18 |
—
|
CVE-2024-10486
The Google for WooCommerce plugin before version 2.8.7 contains an information disclosure vulnerability stemming from an unprotected print_php_information.php file that any visitor can access. Attackers without authentication can leverage this exposure to gather details about the web server and PHP setup, information that could facilitate further exploitation. The flaw affects all installations running version 2.8.6 and earlier.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings