PT-2026-71032 · WordPress · Order Sync With Zendesk For Woocommerce
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Order Sync with Zendesk for WooCommerce versions prior to 2.2.3
Description
An issue exists where a REST API endpoint fails to perform capability checks and does not verify if the requester owns the account being queried. This allows unauthenticated attackers to retrieve the order history and purchase totals of customers by providing an email address that is known or can be enumerated.
Recommendations
Update Order Sync with Zendesk for WooCommerce to version 2.2.3 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Order Sync With Zendesk For Woocommerce