๐Ÿ” CVE Alert

CVE-2026-16568

UNKNOWN 0.0

ShopApper <= 0.4.62 - Subscriber+ Customer Data Disclosure via IDOR

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 does not verify that the requesting user owns the customer profile being queried through one of its REST endpoints, allowing any authenticated user (e.g. a customer/subscriber) to retrieve other users' personal data, including their email address, name, and roles.

Vendor unknown
Product mobile app for woocommerce: shopapper mobile app builder service for woocommerce
Published Aug 27, 2026
Stay Ahead of the Next One

Get instant alerts for unknown mobile app for woocommerce: shopapper mobile app builder service for woocommerce

Be the first to know when new unknown vulnerabilities affecting unknown mobile app for woocommerce: shopapper mobile app builder service for woocommerce are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce
0 โ‰ค 0.4.62

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/489be79d-df68-4384-83ab-c3fa5400eadc/

Credits

TruongLV1 From FPT Night Wolf WPScan