Security Advisory

CVE-2026-14832

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-17 06:00:13
Last updated 2026-08-17 15:35:51
Assigner WPScan
CVSS score 5.3
State PUBLISHED

Description

The ShopSmart Loyalty for WooCommerce WordPress plugin through 1.0.0 does not perform any authorization or ownership check on a phone-number lookup exposed to unauthenticated users, allowing anyone who knows a customer's phone number to retrieve that customer's loyalty profile, including name, email, and account balance.