Description
The Integration for Epos Now and WooCommerce WordPress plugin before 4.11.2 does not perform an authorization check on one of its REST endpoints, allowing unauthenticated users to retrieve the site's scheduled background tasks and their arguments, which include order identifiers and, when WooCommerce's deferred emails feature is enabled, the plaintext passwords of newly registered customers.
Published: 2026-10-07
Score: 5.9 Medium
EPSS: n/a
KEV: No
Impact: Unauthenticated information disclosure of order identifiers and customer passwords
Action: Immediate Patch
AI Analysis

Impact

The vulnerability originates from an authorization check failure on a REST endpoint within the Integration for Epos Now and WooCommerce WordPress plugin. An attacker who can access the endpoint can retrieve the Action Scheduler queue, including the queued tasks and their arguments, which expose order identifiers. When WooCommerce’s deferred emails feature is enabled, the arguments also contain plaintext passwords for newly registered customers. This direct exposure breaches confidentiality and could allow credential theft or account takeover.

Affected Systems

WordPress sites that have the Integration for Epos Now and WooCommerce plugin installed in any version before 4.11.2 (no lower bound specified), and that have WooCommerce enabled with the deferred emails feature for email notifications.

Risk and Exploitability

The attack vector is unauthenticated access to a REST API endpoint, requiring no user credentials or special privileges. Because the endpoint returns sensitive data, the risk to confidentiality is high. The exploit is straightforward: an external actor can issue a simple HTTP request to the unsecured endpoint. While EPSS data is not available and the vulnerability is not listed in KEV, the disclosure of plaintext passwords indicates a serious security issue that could be leveraged in a broader attack chain. The CVSS score of 5.9 indicates a moderate overall severity.

Generated by OpenCVE AI on October 7, 2026 at 11:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Integration for Epos Now and WooCommerce plugin to version 4.11.2 or later
  • If upgrade timing is delayed, temporarily block the vulnerable REST endpoint using a firewall rule or authentication‑blocking plugin
  • Audit other REST endpoints in the plugin for missing authorization checks and apply similar remediation measures if needed

Generated by OpenCVE AI on October 7, 2026 at 11:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 10:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Wed, 07 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Integration for Epos Now and WooCommerce WordPress plugin before 4.11.2 does not perform an authorization check on one of its REST endpoints, allowing unauthenticated users to retrieve the site's scheduled background tasks and their arguments, which include order identifiers and, when WooCommerce's deferred emails feature is enabled, the plaintext passwords of newly registered customers.
Title Integration for Epos Now and WooCommerce 4.6.0 - 4.11.1 - Unauthenticated Action Scheduler Queue Disclosure
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-07T10:09:58.631Z

Reserved: 2026-09-30T12:20:34.063Z

Link: CVE-2026-103323

cve-icon Vulnrichment

Updated: 2026-10-07T09:59:43.245Z

cve-icon NVD

Status : Received

Published: 2026-10-07T07:16:57.047

Modified: 2026-10-07T11:17:08.957

Link: CVE-2026-103323

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T11:30:16Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control

  • CWE-862

    Missing Authorization