PT-2026-73210 · WordPress · Shopsmart Loyalty For Woocommerce
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ShopSmart Loyalty for WooCommerce versions prior to 1.0.1
Description
The ShopSmart Loyalty for WooCommerce WordPress plugin fails to perform authorization or ownership checks on a phone-number lookup feature available to unauthenticated users. An attacker who possesses a customer's phone number can use the
shopsmart check phone function to retrieve the customer's loyalty profile, which includes sensitive information such as name, email, and account balance.Recommendations
Update ShopSmart Loyalty for WooCommerce to a version newer than 1.0.0.
As a temporary mitigation, restrict access to the
shopsmart check phone function to prevent unauthorized information disclosure.Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Shopsmart Loyalty For Woocommerce