CVE-2026-16568
ShopApper <= 0.4.62 - Subscriber+ Customer Data Disclosure via IDOR
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 does not verify that the requesting user owns the customer profile being queried through one of its REST endpoints, allowing any authenticated user (e.g. a customer/subscriber) to retrieve other users' personal data, including their email address, name, and roles.
| Vendor | unknown |
| Product | mobile app for woocommerce: shopapper mobile app builder service for woocommerce |
| Published | Aug 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown mobile app for woocommerce: shopapper mobile app builder service for woocommerce
Be the first to know when new unknown vulnerabilities affecting unknown mobile app for woocommerce: shopapper mobile app builder service for woocommerce are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce
0 โค 0.4.62
References
Credits
TruongLV1 From FPT Night Wolf WPScan