S4E just found a high-severity finding from top 10 tcp port service scan
medium·Product Based Web Vulnerabilities·Updated Apr 4, 2025

CVE-2024-10486 Scanner

CVE-2024-10486 Scanner - Information Disclosure vulnerability in Google for WooCommerce

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-10486
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

The Google for WooCommerce plugin for WordPress is vulnerable to Information Disclosure in all versions up to, and including, 2.8.6. This is due to publicly accessible print_php_information.php file. This makes it possible for unauthenticated attackers to retrieve information about Webserver and PHP configuration, which can be used to aid other attacks.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Google for WooCommerceby woocommerce
0
woocommerceby automattic
0
Updated Aug 22, 2026View on NVD →
Detail

The Google for WooCommerce plugin integrates Google services into WooCommerce, allowing businesses to manage their online store and ads more efficiently. It's widely used by online retailers to enhance their e-commerce capabilities by connecting with Google Ads and Google Analytics. This plugin is crucial for those looking to improve their store's visibility on Google search and ad platforms. Businesses rely on it to streamline their product listings and advertising strategies directly from their WordPress dashboard. It is used by marketers and online store owners to optimize their reach and sales. The tool is highly valued for its seamless integration with Google's ecosystem.

Information Disclosure is a vulnerability where sensitive data is exposed to unauthorized entities due to improper access control or misconfiguration. In this context, the vulnerability is found in the Google for WooCommerce plugin, where sensitive PHP and web server information can be accessed publicly. Such disclosures can inadvertently assist attackers by providing crucial environment details. Attackers could potentially use this information as a stepping stone for more sophisticated attacks on the web application. This type of vulnerability primarily exposes configuration and environment details. Accidental exposures like this are critical as they help attackers craft more targeted exploitation strategies.

The vulnerability in Google for WooCommerce is specifically in the "print_php_information.php" script, publicly accessible, revealing PHP and server configuration. This script exposes sensitive server details without requiring authentication, thus facilitating remote attackers in collecting valuable configuration data. The endpoint in question resides at a well-known location, which makes it particularly susceptible to accidental exposures through public scanning. The combination of "PHP Extension" and "PHP Version" keywords in the server response indicates successful exploitation. This information can be used to map out server configuration with excessive detail. Safeguarding such endpoints by restricting access is crucial to mitigating this disclosure risk effectively.

Exploiting this vulnerability could potentially lead to a series of security risks, including facilitating further targeted attacks. Access to PHP information might help attackers in identifying vulnerable PHP extensions or server misconfigurations. This could lead to tailored attacks exploiting specific server or PHP weaknesses, increasing the risk of unauthorized data breaches. Additionally, knowing the PHP version can help attackers exploit version-specific vulnerabilities to gain further access or cause disruption. Mitigating information disclosure reduces the chances of attackers leveraging disclosed data for malicious means. The failure to address this vulnerability poses persistent security risks to affected WordPress sites.

REFERENCES

Solution Advice
  • Restrict access to sensitive files such as print_php_information.php by using .htaccess or equivalent server-side directives.
  • Implement proper access control measures for all scripts and plugins to prevent unauthorized access.
  • Ensure that sensitive endpoints are not publicly accessible by configuring server security settings appropriately.
  • Regularly update plugins to the latest version to apply security patches and mitigate vulnerabilities.
  • Conduct periodic security audits to identify and remediate potential information disclosure points.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-10486 Scanner - Information Disclosure vulnerability in Google for WooCommerce | S4E