Description
WordPress Plugin WooCommerce Email Test is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information (orders, customer details, email address, cart content, payment type, etc.) that may help in launching further attacks. WordPress Plugin WooCommerce Email Test version 1.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.6 or latest
References
https://www.jansass.com/team-wpscantastic-findet-sicherheitsluecke-in-woocommerce-email-test/
https://wordpress.org/plugins/woocommerce-email-test/changelog/
Related Vulnerabilities
Magento CVE-2019-8123 Vulnerability (CVE-2019-8123)
MySQL Improper Link Resolution Before File Access ('Link Following') Vulnerability (CVE-2009-4030)
WordPress Plugin Admin Menu Tree Page View Multiple Vulnerabilities (2.6.9)
WordPress Plugin StatPress Cross-Site Scripting (1.2.9.1)
PHP Deserialization of Untrusted Data Vulnerability (CVE-2017-11143)