VYPR
High severity8.2NVD Advisory· Published Jul 4, 2024· Updated Apr 15, 2026

CVE-2024-6506

CVE-2024-6506

Description

Information exposure vulnerability in the MRW plugin, in its 5.4.3 version, affecting the "mrw_log" functionality. This vulnerability could allow a remote attacker to obtain other customers' order information and access sensitive information such as name and phone number. This vulnerability also allows an attacker to create or overwrite shipping labels.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1
  • MRW/MRWllm-create
    Range: =5.4.3

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.