Description
Unauthenticated Sensitive Data Exposure in Kit (formerly ConvertKit) for WooCommerce <= 2.1.5 versions.
Published: 2026-07-02
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Unauthenticated users can read confidential data stored by the Kit (formerly ConvertKit) for WooCommerce plugin when it runs on a WordPress site. The flaw, classified as CWE‑497, results from missing authentication checks before data is returned and allows attackers to retrieve personal information, transaction details, or other sensitive content without possessing legitimate credentials.

Affected Systems

WordPress sites that use the Nathanbarry:Kit (formerly ConvertKit) for WooCommerce plugin version 2.1.5 or older are affected. Any WooCommerce installation that includes this plugin can expose user data through the plugin’s exposed interfaces or internal data retrieval mechanisms.

Risk and Exploitability

The CVSS score of 5.3 places the issue in the moderate category. The EPSS score of less than 1% indicates a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit this flaw by sending unauthenticated HTTP requests to the plugin’s data endpoints, retrieving sensitive data without any authentication or privileged access. No evidence of widespread active exploitation is known at the time of analysis. The likely attack vector involves sending unauthenticated HTTP requests to plugin endpoints that expose sensitive data, inferred from the described behaviour.

Generated by OpenCVE AI on July 17, 2026 at 10:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Kit (formerly ConvertKit) for WooCommerce plugin to the latest version that includes the data‑exposure fix.
  • If an upgrade cannot be performed immediately, temporarily disable or remove the plugin from the WordPress site until a patched version is released.
  • Configure WordPress or a security plugin to enforce authentication on any endpoints related to the Kit plugin before returning data.
  • Keep the core WordPress installation, WooCommerce plugin, and all other installed plugins up to date to reduce overall attack surface.

Generated by OpenCVE AI on July 17, 2026 at 10:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Nathanbarry
Nathanbarry kit (formerly Convertkit) For Woocommerce
Wordpress
Wordpress wordpress
Vendors & Products Nathanbarry
Nathanbarry kit (formerly Convertkit) For Woocommerce
Wordpress
Wordpress wordpress

Thu, 02 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated Sensitive Data Exposure in Kit (formerly ConvertKit) for WooCommerce <= 2.1.5 versions.
Title WordPress Kit (formerly ConvertKit) for WooCommerce plugin <= 2.1.5 - Sensitive Data Exposure vulnerability
Weaknesses CWE-497
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Nathanbarry Kit (formerly Convertkit) For Woocommerce
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-02T19:46:08.227Z

Reserved: 2026-06-25T08:04:34.979Z

Link: CVE-2026-57753

cve-icon Vulnrichment

Updated: 2026-07-02T19:46:03.710Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T11:00:06Z

Weaknesses
  • CWE-497

    Exposure of Sensitive System Information to an Unauthorized Control Sphere