CVE-2025-12584
BaseFortify
Publication date: 2025-11-27
Last updated on: 2025-11-27
Assigner: Wordfence
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| woocommerce | quick_view | 2.2.17 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-200 | The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the Quick View for WooCommerce plugin for WordPress, affecting all versions up to and including 2.2.17. It is an Information Exposure issue caused by insufficient restrictions on the 'wqv_popup_content' AJAX endpoint, allowing unauthenticated attackers to access data from private products that should normally be inaccessible.
How can this vulnerability impact me? :
The vulnerability can allow unauthenticated attackers to extract sensitive information from private products on a WooCommerce site. This could lead to unauthorized disclosure of confidential product data, potentially harming business interests or customer privacy.