WordPress · Fluentcart · CVE-2026-14927
**Name of the Vulnerable Software and Affected Versions**
FluentCart A New Era of eCommerce WordPress plugin versions prior to 1.5.3
**Description**
Insufficient authorization and ownership checks occur when rendering customer order documents that use a sequential numeric identifier. This allows unauthenticated visitors to enumerate and disclose sensitive customer personal data, including names, email addresses, billing and shipping postal addresses, and order details.
**Recommendations**
Update the plugin to version 1.5.3 or later.