Sceawere

Vulnerability Detail

CVE-2026-19073UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Order Sync Zendesk Broken Access Control

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
10h ago
Vendor
Unknown
Product
Order Sync with Zendesk for WooCommerce
Attack Type
CWE-200 Information Exposure
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Order Sync with Zendesk for WooCommerce WordPress plugin before 2.2.3 does not perform any capability check on one of its REST API endpoints, and does not verify that the requester owns the account being queried, allowing unauthenticated attackers to retrieve the order history and purchase totals of any customer whose email address they know or can enumerate.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-08-12T06:21:47.157Z",
  "pubdate": "2026-08-12T06:21:47.157Z",
  "executiveSummary": "An access control vulnerability exists within the Order Sync with Zendesk for WooCommerce WordPress plugin affecting versions prior to 2.2.3. The flaw is categorized as an authorization bypass and Insecure Direct Object Reference (IDOR) within a REST API endpoint. The vulnerability allows unauthenticated remote attackers to query and retrieve sensitive customer data, specifically order history and purchase totals, without requiring any prior authentication or privileged access. Exploitation requires knowledge or enumeration of valid customer email addresses. The direct impact includes severe unauthorized disclosure of personally identifiable information and financial purchase history, posing significant privacy risks and potential compliance violations for affected e-commerce stores utilizing the vulnerable plugin.",
  "technicalDetails": "The root cause of the vulnerability stems from inadequate access control implementation and missing capability checks within the REST API endpoint exposed by the Order Sync with Zendesk for WooCommerce plugin. Specifically, the affected endpoint fails to validate whether the incoming HTTP request originates from an authenticated user with administrative or appropriate supervisory capabilities. Furthermore, the endpoint lacks proper session validation and authorization logic to ensure that the entity making the request owns or is legitimately authorized to access the specific customer account data being queried.\nThe vulnerability resides in the custom REST API routing handled by the plugin. Attackers can leverage network exposure to directly interact with the insecure API endpoint via standard HTTP requests. The attack flow involves the enumeration or prior knowledge of target customer email addresses. By supplying a target email address as a parameter within the API request, the vulnerable component processes the query and returns the associated order history and cumulative purchase totals without performing identity verification or authorization checks.\nThe exploitation mechanism relies entirely on the absence of authorization mechanisms. Because the endpoint is publicly accessible over the network and requires no authentication credentials or privilege levels, unauthenticated threat actors can automate requests to scrape sensitive customer financial and transaction data at scale. The post-exploitation impact includes the aggregation of comprehensive customer profiles, exposure of purchasing habits, and potential leveraging of transaction data for secondary social engineering or targeted phishing attacks against customers of the affected WooCommerce store."
}
CVE-2026-19073: Order Sync Zendesk Broken Access Control (MEDIUM Severity, CVSS: 5.3) - Sceawere