Access violation vulnerability in Booster Plus for WooCommerce 7.1.2

The Booster Plus for WooCommerce plugin on WordPress can be accessed by someone who is not authorized to view the data. This is because there is a function that does not have a check to ensure only certain people can access it. This means that anyone who has at least subscriber-level access can see information about orders that they should not have access to.

Detected in:

Booster Plus for WooCommerce fixed vulnerable versions: >= * < 7.1.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.