The WooCommerce Customers Manager WordPress plugin before 29.8 does not have authorisation and CSRF in an AJAX action, allowing any authenticated users, such as subscriber, to call it and retrieve the list of customer email addresses along with their id, first name and last name
CVE ID: CVE-2024-1756
Vendor: Unknown
Product: WooCommerce Customers Manager
EPSS Score: 0.33% (probability of being exploited)
EPSS Percentile: 54.75% (scored less or equal to compared to others)
EPSS Date: 2025-04-18 (when was this score calculated)
SSVC Exploitation: none
SSVC Technical Impact: partial
SSVC Automatable: false