CVE-2024-13820

MEDIUM

Melhor Envio <2.15.9 - Info Disclosure

Title source: llm
STIX 2.1

Description

The Melhor Envio plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.15.11 via the 'run' function, which uses a hardcoded hash. This makes it possible for unauthenticated attackers to extract sensitive data including environment information, plugin tokens, shipping configurations, and limited vendor information.

Scores

CVSS v3 5.3
EPSS 0.0034
EPSS Percentile 25.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (2)
melhorenvio/Melhor Envio < 2.15.11
melhorenvio/Melhor Envio < 2.15.9
Published Apr 08, 2025
Tracked Since Feb 18, 2026