The FluentCart A New Era of eCommerce WordPress plugin before 1.5.3 does not perform any authorization or ownership check before rendering customer order documents keyed on a sequential numeric identifier, allowing unauthenticated visitors to enumerate and disclose customer personal data (names, email addresses, billing and shipping postal addresses, and order details) across the store.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-31 07:16
Updated : 2026-08-26 16:31
NVD link : CVE-2026-14927
Mitre link : CVE-2026-14927
CVE.ORG link : CVE-2026-14927
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
