Get real-time updates on Telegram
Verified
CVE-2026-94275: Track Orders for WooCommerce 0 to before 1.2.7
Affected technology
Track Orders for WooCommerce · 0 to before 1.2.7
Vendor not specified by the source
Description’s affected range: before 1.2.7 does not verify ownership of an order before returning its billing details
Component: Not specified by the source
What an attacker can do
Unauthenticated attackers can obtain a customer's name, email address, phone number, postal address and order history by supplying that customer's email address.
- KEV
- no
Provenance
- GitHub Advisory Database · Source record · observed 2026-10-08 08:50:52.119177+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-08 08:49:39.219831+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-94275.html