Description
WordPress Plugin WooCommerce Email Test is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information (orders, customer details, email address, cart content, payment type, etc.) that may help in launching further attacks. WordPress Plugin WooCommerce Email Test version 1.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.6 or latest
References
https://www.jansass.com/team-wpscantastic-findet-sicherheitsluecke-in-woocommerce-email-test/
https://wordpress.org/plugins/woocommerce-email-test/changelog/
Related Vulnerabilities
MySQL Improper Input Validation Vulnerability (CVE-2017-3256)
WordPress Plugin WordPress Infinite Scroll-Ajax Load More Directory Traversal (5.5.4)
phpMyAdmin Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-6610)
WordPress Plugin Browser Rejector Remote File Inclusion (2.10)
WordPress Plugin Import all XML, CSV & TXT into WordPress Multiple Vulnerabilities (6.5.7)