CVE-2026-14832

The ShopSmart Loyalty for WooCommerce WordPress plugin through 1.0.0 does not perform any authorization or ownership check on a phone-number lookup exposed to unauthenticated users, allowing anyone who knows a customer's phone number to retrieve that customer's loyalty profile, including name, email, and account balance.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-17 06:17

Updated : 2026-08-26 16:30


NVD link : CVE-2026-14832

Mitre link : CVE-2026-14832

CVE.ORG link : CVE-2026-14832


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key