CVE-2026-94275

Published: Ott 08, 2026 Last Modified: Ott 08, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

The Track Orders for WooCommerce WordPress plugin before 1.2.7 does not verify ownership of an order before returning its billing details, allowing unauthenticated attackers to obtain a customer's name, email address, phone number, postal address and order history by supplying that customer's email address.

https://wpscan.com/vulnerability/0037e6ef-5163-4508-9eef-3173a3951fcc/