CyberRota Analysis
AI-GeneratedThe PeproDev WooCommerce Receipt Uploader plugin for WordPress versions up to 2.8.0 is vulnerable due to inadequate verification of access tokens, enabling unauthenticated attackers to forge tokens and access sensitive image attachments, including payment receipts from other customers. This flaw poses a significant risk to user privacy and data security. WordPress site administrators using this plugin should prioritize addressing this vulnerability to protect customer information.
Original NVD Description
The PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 does not verify that a requested attachment belongs to the order referenced by its access token, allowing unauthenticated attackers to forge a token and disclose image attachments, including other customers' uploaded payment receipts, that they do not own.