Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-14927

Опубликовано: 31 июл. 2026
Источник: nvd
CVSS3: 3.7
EPSS Низкий

Описание

The FluentCart A New Era of eCommerce WordPress plugin before 1.5.3 does not perform any authorization or ownership check before rendering customer order documents keyed on a sequential numeric identifier, allowing unauthenticated visitors to enumerate and disclose customer personal data (names, email addresses, billing and shipping postal addresses, and order details) across the store.

EPSS

Процентиль: 6%
0.00162
Низкий

3.7 Low

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 3.7
github
около 2 месяцев назад

The FluentCart A New Era of eCommerce WordPress plugin before 1.5.3 does not perform any authorization or ownership check before rendering customer order documents keyed on a sequential numeric identifier, allowing unauthenticated visitors to enumerate and disclose customer personal data (names, email addresses, billing and shipping postal addresses, and order details) across the store.

EPSS

Процентиль: 6%
0.00162
Низкий

3.7 Low

CVSS3

Дефекты

CWE-639