CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2026-103323: Integration for Epos Now and WooCommerce 4.6.0 to before 4.11.2

CVE-2026-103323. CVSS 3.1 base score 5.9 (MEDIUM, Source advisory).

Affected technology

Integration for Epos Now and WooCommerce · 4.6.0 to before 4.11.2
Vendor not specified by the source

Description’s affected range: before 4.11.2 does not perform an authorization check on one of its REST endpoints

Component: Not specified by the source

Attack conditions (Source advisory, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

Unauthenticated users can retrieve the site's scheduled background tasks and their arguments, which include order identifiers and, when WooCommerce's deferred emails feature is enabled, the plaintext passwords of newly registered customers. Source advisory’s CVSS 3.1 assessment (base score 5.9/10) rates confidentiality impact as high; integrity and availability impact as none.

Published

CWE
CWE-862
CCR priority
23.6 /100 (P4)
CVSS 3.1
5.9 /10 · CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N · Source advisory
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2026-103323.html