[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fCkd6sdyFBeprIDz0O3OgFDS5v8xzK9SYocl91ejOucc":3},{"id":4,"url_slug":5,"title":6,"description":7,"plugin_slug":8,"theme_slug":9,"affected_versions":10,"patched_in_version":11,"severity":12,"cvss_score":13,"cvss_vector":14,"vuln_type":15,"published_date":16,"updated_date":17,"references":18,"days_to_patch":20},"WF-75f0bc5a-f588-4aeb-9e55-72e180d39ddf-woo-alidropship","ald-dropping-and-fulfillment-for-aliexpress-and-woocommerce-missing-authorization-to-order-information-disclosure","ALD Dropping and Fulfillment for AliExpress and WooCommerce \u003C= 1.0.21 - Missing Authorization to Order Information Disclosure","The ALD Dropping and Fulfillment for AliExpress and WooCommerce plugin for WordPress is vulnerable to unauthorized access and modification of data in versions up to, and including, 1.0.21. This is due to missing capability checks on several functions such as the 'update_ali_order_id', 'ob_get_clean', and 'get_ali_order_detail' functions to name a few. This makes it possible for unauthenticated attackers to retrieve order information or possibly make (minor) changes to an order.","woo-alidropship",null,"\u003C=1.0.21","1.0.22","medium",6.3,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:L\u002FUI:N\u002FS:U\u002FC:L\u002FI:L\u002FA:L","Missing Authorization","2023-02-14 00:00:00","2024-01-22 19:56:02",[19],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F75f0bc5a-f588-4aeb-9e55-72e180d39ddf?source=api-prod",343]