Sceawere

Vulnerability Detail

CVE-2026-28169UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
1d ago
Vendor
YITHEMES
Product
YITH WooCommerce Zoom Magnifier
Attack Type
CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-08-06T15:16:53.223Z",
  "pubdate": "2026-08-06T15:16:53.223Z",
  "executiveSummary": "This security assessment analyzes an unauthenticated sensitive data exposure vulnerability affecting the YITH WooCommerce Zoom Magnifier plugin up to version 2.52.0. The vulnerability allows remote, unauthenticated attackers to harvest sensitive information from vulnerable WordPress installations without requiring prior interaction, valid credentials, or specific privilege levels.\nThe flaw stems from improper access controls and insecure data handling within the plugin, enabling unauthorized retrieval of confidential application data over the network. Successful exploitation exposes sensitive system or user data, potentially facilitating further reconnaissance, secondary attacks, or complete compromise of the underlying e-commerce platform.\nGiven the unauthenticated nature of the flaw and the typical exposure of WordPress environments to the public internet, the risk implications are significant. Threat actors can systematically scan for and exploit vulnerable endpoints at scale using automated tooling. Remediation requires immediate attention, specifically focusing on software updates and access restriction controls to mitigate exposure.",
  "technicalDetails": "The vulnerability resides in the YITH WooCommerce Zoom Magnifier plugin for WordPress, specifically impacting all versions up to and including 2.52.0. The root cause of the issue is the lack of proper authentication checks and inadequate authorization enforcement on internal functionality handling sensitive requests.\nFrom a network exposure perspective, the vulnerable component is accessible over HTTP/HTTPS without requiring any session tokens, cookies, or user credentials. An unauthenticated remote attacker can interact directly with the vulnerable endpoint to trigger the sensitive data exposure vector.\nThe attack flow proceeds as follows: First, the attacker identifies a target running an affected version of YITH WooCommerce Zoom Magnifier (<= 2.52.0). Second, the attacker formulates a crafted HTTP request directed at the specific vulnerable functionality or AJAX/REST endpoint exposed by the plugin. Third, because the application fails to validate the requester's authentication state or capability to access the requested resource, the server processes the payload and returns the sensitive data within the HTTP response body.\nPost-exploitation impact includes the unauthorized disclosure of confidential information, which may encompass internal configuration details, database records, or sensitive user-related data processed by the WooCommerce ecosystem. This intelligence can subsequently be leveraged by malicious actors to mount targeted attacks against the administrative interface, registered users, or integrated payment systems."
}
CVE-2026-28169: Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier (MEDIUM Severity, CVSS: 5.3) - Sceawere