The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.1.2 via the 'file_url' parameter. This makes it possible for unauthenticated attackers to view potentially sensitive information and download a digital product without paying for it.
Metrics
Affected Vendors & Products
References
History
Wed, 23 Apr 2025 07:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The WordPress Simple Shopping Cart plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.1.2 via the 'file_url' parameter. This makes it possible for unauthenticated attackers to view potentially sensitive information and download a digital product without paying for it. | |
Title | WordPress Simple PayPal Shopping Cart <= 5.1.2 - Unauthenticated Information Exposure via file_url Parameter | |
Weaknesses | CWE-201 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: Wordfence
Published: 2025-04-23T07:06:49.072Z
Updated: 2025-04-23T18:22:39.548Z
Reserved: 2025-04-11T20:42:09.953Z
Link: CVE-2025-3529

No data.

Status : Awaiting Analysis
Published: 2025-04-23T08:15:14.527
Modified: 2025-04-23T14:08:13.383
Link: CVE-2025-3529

No data.