PT-2026-66709 · WordPress · Fluentcart

·

CVE-2026-14927

·

Published

2026-07-31

·

Updated

2026-07-31

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions FluentCart A New Era of eCommerce WordPress plugin versions prior to 1.5.3
Description Insufficient authorization and ownership checks occur when rendering customer order documents that use a sequential numeric identifier. This allows unauthenticated visitors to enumerate and disclose sensitive customer personal data, including names, email addresses, billing and shipping postal addresses, and order details.
Recommendations Update the plugin to version 1.5.3 or later.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14927

Affected Products

Fluentcart