Description
The Ni WooCommerce Sales Report WordPress plugin before 4.2.0 does not have any authentication or authorisation checks on one of its report-printing routines, allowing unauthenticated users to retrieve WooCommerce order details and customer contact information, to target an individual order, and to search the store's orders by customer name or email address.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated Data Disclosure
Action: Apply Patch
AI Analysis

Impact

The Ni WooCommerce Sales Report WordPress plugin versions earlier than 4.2.0 lack both authentication and authorization checks on a report‑printing routine that accepts a 'btn_print' parameter. An attacker can invoke this routine without logging in, prompting the plugin to return detailed WooCommerce order data, including billing and shipping addresses, as well as customer contact information. The disclosed data may contain personal identifiers, financial details, and order history, which can be leveraged for identity theft, fraud, or further compromise.

Affected Systems

Any WordPress site that has the Ni WooCommerce Sales Report plugin installed with a version older than 4.2.0 is affected. The vulnerability is specific to the WordPress plugin and does not involve other components or operating systems beyond the WordPress installation that hosts the plugin.

Risk and Exploitability

The vulnerability is accessed via a standard HTTP request to the plugin’s print endpoint, which is reachable from the public web. The CVSS score of 5.3 classifies it as medium severity, and the EPSS score of less than 1% indicates a very low but non‑zero likelihood of exploitation. It is currently not listed in CISA’s KEV catalog, suggesting no widespread exploitation has been reported. Despite the low exploit probability, the sensitive nature of the exposed data warrants prompt mitigation.

Generated by OpenCVE AI on September 20, 2026 at 05:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Ni WooCommerce Sales Report plugin to version 4.2.0 or later, which reinserts the missing authentication checks.
  • If an upgrade cannot be performed immediately, block or require authentication for requests to the '/btn_print' endpoint using web‑server or firewall rules to prevent unauthenticated access.
  • Review the site’s logs and database for any previously exposed order or customer information and clean or redact it if necessary.

Generated by OpenCVE AI on September 20, 2026 at 05:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 11:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Wed, 16 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Ni WooCommerce Sales Report WordPress plugin before 4.2.0 does not have any authentication or authorisation checks on one of its report-printing routines, allowing unauthenticated users to retrieve WooCommerce order details and customer contact information, to target an individual order, and to search the store's orders by customer name or email address.
Title Ni WooCommerce Sales Report < 4.2.0 - Unauthenticated Order and Customer Data Disclosure via 'btn_print' Parameter
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-17T12:38:54.114Z

Reserved: 2026-08-24T16:51:40.717Z

Link: CVE-2026-78474

cve-icon Vulnrichment

Updated: 2026-09-17T12:20:33.241Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T06:16:32.923

Modified: 2026-09-17T13:16:47.957

Link: CVE-2026-78474

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:15:16Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor