PT-2026-71032 · WordPress · Order Sync With Zendesk For Woocommerce

·

CVE-2026-19073

·

Published

2026-08-12

·

Updated

2026-08-12

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Order Sync with Zendesk for WooCommerce versions prior to 2.2.3
Description An issue exists where a REST API endpoint fails to perform capability checks and does not verify if the requester owns the account being queried. This allows unauthenticated attackers to retrieve the order history and purchase totals of customers by providing an email address that is known or can be enumerated.
Recommendations Update Order Sync with Zendesk for WooCommerce to version 2.2.3 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19073

Affected Products

Order Sync With Zendesk For Woocommerce