CVE · Medium

CVE-2024-13820 — Melhor Envio [melhor-envio-cotacao] < 2.15.12

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-13820 Melhor Envio [melhor-envio-cotacao] < 2.15.12 Exposure of Sensitive Information to an Unauthorized Actor Medium 5.3 < 2.15.12 2.15.12 2025-04-07

CVE-2024-13820

The Melhor Envio plugin for WordPress contains a sensitive information exposure flaw in versions up to 2.15.11 affecting the 'run' function, which relies on a hardcoded hash value. This vulnerability allows unauthenticated attackers to access protected data such as environment details, plugin tokens, shipping settings, and vendor information. The issue has been patched in version 2.15.12 and later releases.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.