PT-2026-66709 · WordPress · Fluentcart
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
FluentCart A New Era of eCommerce WordPress plugin versions prior to 1.5.3
Description
Insufficient authorization and ownership checks occur when rendering customer order documents that use a sequential numeric identifier. This allows unauthenticated visitors to enumerate and disclose sensitive customer personal data, including names, email addresses, billing and shipping postal addresses, and order details.
Recommendations
Update the plugin to version 1.5.3 or later.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fluentcart