Description
WordPress Plugin WooCommerce Email Test is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information (orders, customer details, email address, cart content, payment type, etc.) that may help in launching further attacks. WordPress Plugin WooCommerce Email Test version 1.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.6 or latest
References
https://www.jansass.com/team-wpscantastic-findet-sicherheitsluecke-in-woocommerce-email-test/
https://wordpress.org/plugins/woocommerce-email-test/changelog/
Related Vulnerabilities
WordPress Plugin MailPoet Newsletters (Previous) Cross-Site Scripting (2.6.19)
MySQL CVE-2018-3203 Vulnerability (CVE-2018-3203)
Contao Weak Password Recovery Mechanism for Forgotten Password Vulnerability (CVE-2019-10641)
WordPress Plugin MPL-Publisher-Create your Ebook & Audiobook Cross-Site Scripting (1.30.2)