Access violation vulnerability in WooCommerce 4.0

The WooCommerce and WooCommerce Admin plugins for WordPress have a potential vulnerability that could allow attackers to access sensitive data related to report analytics. These plugins are used on WordPress websites and are vulnerable in versions up to 5.7.0 for WooCommerce and 2.6.4 for WooCommerce Admin. The vulnerability is caused by a lack of protection of the directory where the analytics reports are stored, making it easier for attackers to access these reports.

Detected in:

WooCommerce fixed vulnerable versions: >= * < 4.0
WooCommerce Admin open vulnerable versions: >= * <= 1.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.