HomeDefault status
unaffected
Any version before 1.3.1
affected
Description
The Fortis for WooCommerce WordPress plugin before 1.3.1 may leak sensitive API keys to unauthenticated attackers, allowing them to query Fortis' API and retrieve sensitive customer information, like past orders, PII, etc.
Problem types
Product status
Any version before 1.3.1
Credits
WPScan Team
WPScan
References
wpscan.com/...rability/220f72ea-e3b4-44c9-8c9b-15662aebb6cb/