CVE-2017-3211: Yopify

Medium severity, CVSS 5.3. EPSS: 0.8% chance of exploitation in the next 30 days.

Yopify, an e-commerce notification plugin, up to April 06, 2017, leaks the first name, last initial, city, and recent purchase data of customers, all without user authorization.

Affected products

  • Yopify Yopify: up to and including 2017-04-06

Published 2020-01-15. Last modified 2026-06-17.