CVE-2026-94275
Received Received - Intake

Unauthenticated Order Data Exposure in Track Orders for WooCommerce

Vulnerability report for CVE-2026-94275, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: WPScan

Description

The Track Orders for WooCommerce WordPress plugin before 1.2.7 does not verify ownership of an order before returning its billing details, allowing unauthenticated attackers to obtain a customer's name, email address, phone number, postal address and order history by supplying that customer's email address.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown Track Orders for WooCommerce 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Track Orders for WooCommerce WordPress plugin before version 1.2.7. It allows unauthenticated attackers to access a customer's billing details by providing their email address without verifying order ownership. This exposes sensitive personally identifiable information (PII) such as name, email, phone number, postal address, and order history.

Detection Guidance

To detect this vulnerability, check if the Track Orders for WooCommerce plugin version is below 1.2.7. You can use commands like 'wp plugin list' in WordPress CLI or inspect the plugin files directly. If the version is outdated, the system is vulnerable.

Impact Analysis

Unauthenticated attackers can exploit this to steal customer data by simply entering an email address. This leads to privacy breaches, potential identity theft, and misuse of personal information. Businesses using the vulnerable plugin risk reputational damage and legal consequences due to exposed customer data.

Compliance Impact

This vulnerability likely violates GDPR and other privacy regulations by failing to protect personal data. GDPR requires strict controls for PII access and disclosure. A breach could result in fines, legal penalties, and mandatory breach notifications under GDPR Article 33 and 34.

Mitigation Strategies

Immediately update the Track Orders for WooCommerce plugin to version 1.2.7 or later. If updating is not possible, consider disabling the plugin temporarily until a patch is applied. Review access logs for suspicious requests querying customer data via email addresses.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-94275. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart