Description
The Track Orders for WooCommerce WordPress plugin before 1.2.7 does not verify ownership of an order before returning its billing details, allowing unauthenticated attackers to obtain a customer's name, email address, phone number, postal address and order history by supplying that customer's email address.
Published: 2026-10-08
Score: n/a
EPSS: n/a
KEV: No
Impact: Unauthenticated PII Disclosure
Action: Patch Immediately
AI Analysis

Impact

The Track Orders for WooCommerce plugin, before version 1.2.7, allows an unauthenticated attacker to retrieve billing details such as a customer’s name, email address, phone number, postal address, and order history simply by providing an email address. The flaw arises because the plugin does not verify that the requester owns the order before exposing billing data, constituting an information exposure vulnerability rooted in improper access control.

Affected Systems

This weakness affects the WordPress plugin Track Orders for WooCommerce on installations running any version prior to 1.2.7. Vulnerability is tied to the plugin’s public-facing order tracking functionality and is exploitable on any WordPress site that uses the affected plugin without additional access restrictions.

Risk and Exploitability

The absence of authentication or ownership checks means that any user with knowledge of a target email address can harvest personal data. While there is no reported exploitation probability (EPSS is not available) and the vulnerability is not listed in CISA’s KEV catalog, the potential to expose sensitive customer information warrants high risk. Attackers could leverage the exposed data for phishing, identity theft or targeted social engineering. The weakness is reachable through the plugin’s email parameter endpoint, making it a likely attack vector for automated or manual enumeration of customer accounts.

Generated by OpenCVE AI on October 8, 2026 at 07:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Track Orders for WooCommerce plugin to version 1.2.7 or later, which includes ownership verification before returning billing details.
  • Restrict the order-tracking endpoint to authenticated users or add IP‑based access controls to limit exposure.
  • Audit and, if necessary, remove or disable the plugin on sites that do not require its functionality, or enforce strict access policies to protect customer PII.

Generated by OpenCVE AI on October 8, 2026 at 07:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284

Thu, 08 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Track Orders for WooCommerce WordPress plugin before 1.2.7 does not verify ownership of an order before returning its billing details, allowing unauthenticated attackers to obtain a customer's name, email address, phone number, postal address and order history by supplying that customer's email address.
Title Track Orders for WooCommerce < 1.2.7 - Unauthenticated PII Disclosure via 'email' Parameter
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-08T06:00:09.401Z

Reserved: 2026-09-21T09:21:47.280Z

Link: CVE-2026-94275

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T06:16:47.457

Modified: 2026-10-08T06:16:47.457

Link: CVE-2026-94275

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T07:45:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control