Sceawere
Vulnerability Detail
CVE-2026-94275UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated IDOR Order Data Exposure
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- Track Orders for WooCommerce
- Attack Type
- CWE-200 Information Exposure
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Track Orders for WooCommerce WordPress plugin before 1.2.7 does not verify ownership of an order before returning its billing details, allowing unauthenticated attackers to obtain a customer's name, email address, phone number, postal address and order history by supplying that customer's email address.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-08T06:16:47.457Z",
"pubdate": "2026-10-08T06:16:47.457Z",
"executiveSummary": "The Track Orders for WooCommerce WordPress plugin versions prior to 1.2.7 contain a critical Insecure Direct Object Reference (IDOR) vulnerability. This flaw arises from a failure to perform adequate authorization checks on order lookup requests. By manipulating input parameters, an unauthenticated attacker can retrieve sensitive Personally Identifiable Information (PII) associated with any arbitrary customer.\nThe vulnerability exposes billing details including full names, email addresses, phone numbers, and physical mailing addresses, alongside complete order history records. This represents a significant breach of data privacy and compliance standards (such as GDPR or CCPA). Given that no authentication or specialized privileges are required to initiate the lookup, the attack surface is exposed to the public internet, posing a severe risk to customer confidentiality and organizational reputation.",
"technicalDetails": "The root cause of this vulnerability is an improper access control implementation within the order tracking functionality of the Track Orders for WooCommerce plugin. The application fails to validate the requestor's identity against the requested order ownership. Specifically, the backend logic accepts an email address as a lookup parameter to fetch order-related metadata without requiring session-based authentication or nonce verification to prove that the requestor is the legitimate owner of the target order.\nThe exploitation process follows a predictable, unauthenticated workflow. An attacker identifies the endpoint responsible for order tracking, typically accessible via a public-facing URL provided by the plugin. By supplying a target customer's email address in the request parameters, the plugin executes a query against the WooCommerce database to retrieve records associated with that address. Because the function lacks an authorization check—such as validating an active customer session or a secure, cryptographically signed token—the server blindly returns the associated billing details and order history contained within the result set.\nThe technical impact is defined by the unauthorized disclosure of PII. Attackers can iterate through known or guessed email addresses to harvest bulk customer data. This data could subsequently be leveraged for downstream attacks, such as targeted phishing, identity theft, or social engineering campaigns against customers. The absence of rate limiting or authentication requirements facilitates automated, large-scale data exfiltration.\nThe vulnerability resides within the plugin's core order lookup logic, affecting all versions prior to 1.2.7. As the exploit requires nothing more than an HTTP request to the vulnerable endpoint, it is classified as a low-complexity attack requiring no specialized authentication or interaction with the victim. Successful exploitation provides immediate read-access to restricted database objects that should have been protected by the WordPress user-session management framework."
}