The Track Orders for WooCommerce WordPress plugin before 1.2.7 does not verify ownership of an order before returning its billing details, allowing unauthenticated attackers to obtain a customer's name, email address, phone number, postal address and order history by supplying that customer's email address.
CVE-2026-94275
NONE
Updated Oct 08, 2026
WordPress
unknown:track orders for woocommerce
CVE Details
CVE ID
CVE-2026-94275
Published Date
Oct 08, 2026
Vendor
WordPress
Severity
NONE
Impact
Minimal impact
Source
View Advisory