The PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 does not verify that a requested attachment belongs to the order referenced by its access token, allowing unauthenticated attackers to forge a token and disclose image attachments, including other customers' uploaded payment receipts, that they do not own.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-06 07:16
Updated : 2026-08-26 16:31
NVD link : CVE-2026-14314
Mitre link : CVE-2026-14314
CVE.ORG link : CVE-2026-14314
JSON object : View
Products Affected
No product.
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
