CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 8.2. It may be remotely exploitable.
CVE
CVE-2024-6506
Severity
HIGH
CVSS
8.2
EPSS
0.50%
Original NVD Description
Information exposure vulnerability in the MRW plugin, in its 5.4.3 version, affecting the "mrw_log" functionality. This vulnerability could allow a remote attacker to obtain other customers' order information and access sensitive information such as name and phone number. This vulnerability also allows an attacker to create or overwrite shipping labels.