CVE-2026-61945
MEDIUM
6.5
CVSS 3.1
Description
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data.
This issue affects WooCommerce Product Stock Alert: from n/a through 3.0.6.
Metadata
Severity & Metrics
6.5
MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| MultiVendorX | WooCommerce Product Stock Alert | — | n/a ≤ 3.0.6 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-497 | cna | CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere |
CVSS scores (1)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 6.5 | MEDIUM | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |