CVE-2026-14927
FluentCart < 1.5.3 - Unauthenticated Order PII Disclosure via Print Routes
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The FluentCart A New Era of eCommerce WordPress plugin before 1.5.3 does not perform any authorization or ownership check before rendering customer order documents keyed on a sequential numeric identifier, allowing unauthenticated visitors to enumerate and disclose customer personal data (names, email addresses, billing and shipping postal addresses, and order details) across the store.
| Vendor | unknown |
| Product | fluentcart a new era of ecommerce |
| Published | Jul 31, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown fluentcart a new era of ecommerce
Be the first to know when new unknown vulnerabilities affecting unknown fluentcart a new era of ecommerce are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / FluentCart A New Era of eCommerce
0 < 1.5.3
References
Credits
Diogo Pinto WPScan