WordPress · Shopsmart Loyalty For Woocommerce · CVE-2026-14832
**Name of the Vulnerable Software and Affected Versions**
ShopSmart Loyalty for WooCommerce versions prior to 1.0.1
**Description**
The ShopSmart Loyalty for WooCommerce WordPress plugin fails to perform authorization or ownership checks on a phone-number lookup feature available to unauthenticated users. An attacker who possesses a customer's phone number can use the `shopsmart check phone` function to retrieve the customer's loyalty profile, which includes sensitive information such as name, email, and account balance.
**Recommendations**
Update ShopSmart Loyalty for WooCommerce to a version newer than 1.0.0.
As a temporary mitigation, restrict access to the `shopsmart check phone` function to prevent unauthorized information disclosure.