CVE-2026-19073
Order Sync with Zendesk for WooCommerce < 2.2.3 - Unauthenticated Customer Order Data Disclosure
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Order Sync with Zendesk for WooCommerce WordPress plugin before 2.2.3 does not perform any capability check on one of its REST API endpoints, and does not verify that the requester owns the account being queried, allowing unauthenticated attackers to retrieve the order history and purchase totals of any customer whose email address they know or can enumerate.
| Vendor | unknown |
| Product | order sync with zendesk for woocommerce |
| Published | Aug 12, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown order sync with zendesk for woocommerce
Be the first to know when new unknown vulnerabilities affecting unknown order sync with zendesk for woocommerce are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Order Sync with Zendesk for WooCommerce
0 < 2.2.3
References
Credits
Shikhali Jamalzade WPScan