Sceawere

Vulnerability Detail

CVE-2026-94275UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated IDOR Order Data Exposure

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
8h ago
Vendor
Unknown
Product
Track Orders for WooCommerce
Attack Type
CWE-200 Information Exposure
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Track Orders for WooCommerce WordPress plugin before 1.2.7 does not verify ownership of an order before returning its billing details, allowing unauthenticated attackers to obtain a customer's name, email address, phone number, postal address and order history by supplying that customer's email address.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-10-08T06:16:47.457Z",
  "pubdate": "2026-10-08T06:16:47.457Z",
  "executiveSummary": "The Track Orders for WooCommerce WordPress plugin versions prior to 1.2.7 contain a critical Insecure Direct Object Reference (IDOR) vulnerability. This flaw arises from a failure to perform adequate authorization checks on order lookup requests. By manipulating input parameters, an unauthenticated attacker can retrieve sensitive Personally Identifiable Information (PII) associated with any arbitrary customer.\nThe vulnerability exposes billing details including full names, email addresses, phone numbers, and physical mailing addresses, alongside complete order history records. This represents a significant breach of data privacy and compliance standards (such as GDPR or CCPA). Given that no authentication or specialized privileges are required to initiate the lookup, the attack surface is exposed to the public internet, posing a severe risk to customer confidentiality and organizational reputation.",
  "technicalDetails": "The root cause of this vulnerability is an improper access control implementation within the order tracking functionality of the Track Orders for WooCommerce plugin. The application fails to validate the requestor's identity against the requested order ownership. Specifically, the backend logic accepts an email address as a lookup parameter to fetch order-related metadata without requiring session-based authentication or nonce verification to prove that the requestor is the legitimate owner of the target order.\nThe exploitation process follows a predictable, unauthenticated workflow. An attacker identifies the endpoint responsible for order tracking, typically accessible via a public-facing URL provided by the plugin. By supplying a target customer's email address in the request parameters, the plugin executes a query against the WooCommerce database to retrieve records associated with that address. Because the function lacks an authorization check—such as validating an active customer session or a secure, cryptographically signed token—the server blindly returns the associated billing details and order history contained within the result set.\nThe technical impact is defined by the unauthorized disclosure of PII. Attackers can iterate through known or guessed email addresses to harvest bulk customer data. This data could subsequently be leveraged for downstream attacks, such as targeted phishing, identity theft, or social engineering campaigns against customers. The absence of rate limiting or authentication requirements facilitates automated, large-scale data exfiltration.\nThe vulnerability resides within the plugin's core order lookup logic, affecting all versions prior to 1.2.7. As the exploit requires nothing more than an HTTP request to the vulnerable endpoint, it is classified as a low-complexity attack requiring no specialized authentication or interaction with the victim. Successful exploitation provides immediate read-access to restricted database objects that should have been protected by the WordPress user-session management framework."
}
CVE-2026-94275: Unauthenticated IDOR Order Data Exposure (MEDIUM Severity, CVSS: 5.3) | Sceawere