CVE-2026-16568
Received Received - Intake

Authentication Bypass Exposes WooCommerce Customer Data

Vulnerability report for CVE-2026-16568, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-27

Last updated on: 2026-08-27

Assigner: WPScan

Description

The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 does not verify that the requesting user owns the customer profile being queried through one of its REST endpoints, allowing any authenticated user (e.g. a customer/subscriber) to retrieve other users' personal data, including their email address, name, and roles.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-27
Last Modified
2026-08-27
Generated
2026-08-27
AI Q&A
2026-08-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
shopapper mobile_app_for_woocommerce to 0.4.66 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Insecure Direct Object Reference (IDOR) flaw in the ShopApper Mobile App Builder Service for WooCommerce WordPress plugin. It allows any authenticated user, including subscribers, to access other users' personal data such as email addresses, names, and roles by querying a REST endpoint without proper ownership verification.

Detection Guidance

To detect this vulnerability, check if your WooCommerce Mobile App plugin version is 0.4.66 or below. Use commands like 'wp plugin list' in WordPress CLI or inspect the plugin files for version details. Test REST endpoints for unauthorized data access by querying user endpoints with different user IDs.

Impact Analysis

This vulnerability can expose sensitive personal data of users, including email addresses, names, and roles. If you use the affected plugin versions, attackers with basic authentication could retrieve this information, leading to privacy breaches and potential misuse of user data.

Compliance Impact

This vulnerability likely violates GDPR and other privacy regulations by exposing personal data without proper access controls. It could result in non-compliance penalties, reputational damage, and loss of user trust due to unauthorized data access.

Mitigation Strategies

Immediately update the ShopApper plugin to the latest version above 0.4.66. If an update is unavailable, consider disabling the plugin temporarily. Review user roles and permissions to ensure least privilege access. Monitor for unauthorized data access attempts in logs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16568. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart