WordPress · Shopapper Mobile App Builder Service For Woocommerce · CVE-2026-16568
**Name of the Vulnerable Software and Affected Versions**
ShopApper Mobile App Builder Service for WooCommerce WordPress plugin versions prior to 0.4.63
**Description**
An issue exists where the plugin fails to verify if the requesting user owns the customer profile being queried via a REST endpoint. This allows any authenticated user, such as a customer or subscriber, to retrieve personal data of other users, including their name, email address, and roles.
**Recommendations**
Update the ShopApper Mobile App Builder Service for WooCommerce WordPress plugin to version 0.4.63 or later.