PT-2026-82387 · WordPress · Shopapper Mobile App Builder Service For Woocommerce
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ShopApper Mobile App Builder Service for WooCommerce WordPress plugin versions prior to 0.4.63
Description
An issue exists where the plugin fails to verify if the requesting user owns the customer profile being queried via a REST endpoint. This allows any authenticated user, such as a customer or subscriber, to retrieve personal data of other users, including their name, email address, and roles.
Recommendations
Update the ShopApper Mobile App Builder Service for WooCommerce WordPress plugin to version 0.4.63 or later.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Shopapper Mobile App Builder Service For Woocommerce