CVE-2026-14314
Received Received - Intake

Unauthenticated Attachment Access in PeproDev WooCommerce Receipt Uploader

Vulnerability report for CVE-2026-14314, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-06

Assigner: WPScan

Description

The PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 does not verify that a requested attachment belongs to the order referenced by its access token, allowing unauthenticated attackers to forge a token and disclose image attachments, including other customers' uploaded payment receipts, that they do not own.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-06
Generated
2026-08-06
AI Q&A
2026-08-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
peprodev woocommerce_receipt_uploader 2.8.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Insecure Direct Object Reference (IDOR) flaw in the PeproDev WooCommerce Receipt Uploader WordPress plugin up to version 2.8.0. It allows unauthenticated attackers to forge access tokens and view image attachments, including other customers' payment receipts, that they are not authorized to access.

Detection Guidance

Check for unauthorized access to receipt attachments by reviewing server logs for unusual requests to the plugin's attachment endpoints. Look for requests with forged tokens or attempts to access files outside assigned orders.

Impact Analysis

Attackers could steal sensitive files like payment receipts uploaded by other customers. This could lead to financial fraud, identity theft, or exposure of confidential business or personal information.

Compliance Impact

This vulnerability likely violates GDPR and HIPAA due to unauthorized access to personal and financial data. It could result in legal penalties, fines, and reputational damage for organizations handling protected health or payment information.

Mitigation Strategies

Update the PeproDev WooCommerce Receipt Uploader plugin to the latest version if available. If no update exists, disable the plugin immediately and restrict access to the upload directory. Monitor for suspicious activity in receipt attachments.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14314. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart