SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-14927

LOW · CVSS 3.7 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-07-31 · Last synced 2026-08-30

CyberRota Analysis

AI-Generated

The FluentCart WordPress plugin prior to version 1.5.3 is vulnerable due to a lack of authorization checks, enabling unauthenticated users to access and enumerate customer order documents using sequential numeric identifiers. This flaw can lead to the exposure of sensitive personal data, including names, email addresses, and order details. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential data breaches.

CVE
CVE-2026-14927
Severity
LOW
CVSS
3.7
EPSS
0.16%
WordPress

Original NVD Description

The FluentCart A New Era of eCommerce WordPress plugin before 1.5.3 does not perform any authorization or ownership check before rendering customer order documents keyed on a sequential numeric identifier, allowing unauthenticated visitors to enumerate and disclose customer personal data (names, email addresses, billing and shipping postal addresses, and order details) across the store.