PT-2026-73210 · WordPress · Shopsmart Loyalty For Woocommerce

·

CVE-2026-14832

·

Published

2026-08-17

·

Updated

2026-08-17

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions ShopSmart Loyalty for WooCommerce versions prior to 1.0.1
Description The ShopSmart Loyalty for WooCommerce WordPress plugin fails to perform authorization or ownership checks on a phone-number lookup feature available to unauthenticated users. An attacker who possesses a customer's phone number can use the shopsmart check phone function to retrieve the customer's loyalty profile, which includes sensitive information such as name, email, and account balance.
Recommendations Update ShopSmart Loyalty for WooCommerce to a version newer than 1.0.0. As a temporary mitigation, restrict access to the shopsmart check phone function to prevent unauthorized information disclosure.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14832

Affected Products

Shopsmart Loyalty For Woocommerce