Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-16039

Опубликовано: 07 авг. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

The MStore API WordPress plugin before 4.21.0 does not restrict its vendor-orders endpoint to the caller's own orders, allowing any authenticated user, including Subscribers, to read every WooCommerce order in the store together with each customer's personal information.

EPSS

Процентиль: 10%
0.00201
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 6.5
github
12 дней назад

The MStore API WordPress plugin before 4.21.0 does not restrict its vendor-orders endpoint to the caller's own orders, allowing any authenticated user, including Subscribers, to read every WooCommerce order in the store together with each customer's personal information.

EPSS

Процентиль: 10%
0.00201
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-639