Vulnerability in WooCommerce 2.1.6
WooCommerce 2.1.6 contains a vulnerability capable to display any post title of any type. This is included since 2.0. It therefore becomes possible, modifying the purchase address directly in the address bar, to display post title from any type and any status. We can display titles from drafts, pendings, protected, et other Custom Post Type even if not designed to be displayed in front-end. Knowing that it exists […]