Description
The Download Manager and Payment Form WordPress Plugin – WP SmartPay plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 1.1.0 to 2.7.13 via the show() function due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view other user's data like email address, name, and notes.
Problem types
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
Product status
1.1.0 (semver)
Timeline
| 2025-05-06: | Disclosed |
Credits
Kenneth Dunn
References
www.wordfence.com/...-b69d-4134-a4f7-78372a291557?source=cve
plugins.trac.wordpress.org/...rs/Rest/CustomerController.php