CVE-2026-19073

The Order Sync with Zendesk for WooCommerce WordPress plugin before 2.2.3 does not perform any capability check on one of its REST API endpoints, and does not verify that the requester owns the account being queried, allowing unauthenticated attackers to retrieve the order history and purchase totals of any customer whose email address they know or can enumerate.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-12 06:21

Updated : 2026-08-26 16:30


NVD link : CVE-2026-19073

Mitre link : CVE-2026-19073

CVE.ORG link : CVE-2026-19073


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor