Impact
The ShopSmart Loyalty for WooCommerce plugin exposes a phone‑number lookup endpoint that performs no authorization or ownership checks. An attacker who knows a customer’s phone number can retrieve that customer’s loyalty profile, including name, email address, and account balance, allowing the exposure of personal data. The vulnerability may enable identity theft, fraud, or targeted phishing, though this potential use case is inferred from the disclosed data.
Affected Systems
This issue affects any WordPress site that incorporates the ShopSmart Loyalty for WooCommerce plugin version 1.0.0 or earlier. The plugin, distributed by an unknown vendor, is employed to manage customer loyalty datasets within WooCommerce installations.
Risk and Exploitability
The vulnerability can be accessed by unauthenticated users over the internet (inferred). The EPSS score is < 1%, and the vulnerability is not listed in CISA’s KEV catalog. The CVSS score of 5.3 quantifies the severity; however, the potential impact on privacy and account integrity is inferred to be significant if exploited.
OpenCVE Enrichment