๐Ÿ” CVE Alert

CVE-2026-19073

UNKNOWN 0.0

Order Sync with Zendesk for WooCommerce < 2.2.3 - Unauthenticated Customer Order Data Disclosure

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Order Sync with Zendesk for WooCommerce WordPress plugin before 2.2.3 does not perform any capability check on one of its REST API endpoints, and does not verify that the requester owns the account being queried, allowing unauthenticated attackers to retrieve the order history and purchase totals of any customer whose email address they know or can enumerate.

Vendor unknown
Product order sync with zendesk for woocommerce
Published Aug 12, 2026
Stay Ahead of the Next One

Get instant alerts for unknown order sync with zendesk for woocommerce

Be the first to know when new unknown vulnerabilities affecting unknown order sync with zendesk for woocommerce are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Order Sync with Zendesk for WooCommerce
0 < 2.2.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/8c8ca8ff-e0e8-4e9c-b79b-7f95816a9113/

Credits

Shikhali Jamalzade WPScan