CVE-2021-25009
The CorreosExpress WordPress plugin through 2.6.0 generates log files which are publicly accessible, and contain sensitive information such as sender/receiver names, phone numbers, physical and email addresses
- Affected products
- Correosexpress
- Correosexpress Project Correosexpress
- ≤ 2.6.0
- Fix
- Available
- CVSS 3.1
- 5.3 MEDIUM
- EPSS
- 1.2% (66th percentile)
- Weakness
- CWE-532
- NVD status
- Modified
- Published
- 2022-03-07
CVE-2021-25009 at NVD
1 known exploit for CVE-2021-25009
Proof-of-concept code and exploit modules indexed by Sploitus