The Booster for WooCommerce for WordPress, up to and including version 7.1.0, has a vulnerability which allows attackers with a subscriber-level or higher access to retrieve sensitive information. This is done through the ‘wcj_wp_option’ shortcode, which does not have sufficient controls on the information it can access.