CVE-2026-94275
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Oct 08, 2026
Vendor
unknown
Description
The Track Orders for WooCommerce WordPress plugin before 1.2.7 does not verify ownership of an order before returning its billing details, allowing unauthenticated attackers to obtain a customer's name, email address, phone number, postal address and order history by supplying that customer's email address.