CVE-2026-94275
Track Orders for WooCommerce < 1.2.7 - Unauthenticated PII Disclosure via 'email' Parameter
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Track Orders for WooCommerce WordPress plugin before 1.2.7 does not verify ownership of an order before returning its billing details, allowing unauthenticated attackers to obtain a customer's name, email address, phone number, postal address and order history by supplying that customer's email address.
| Vendor | unknown |
| Product | track orders for woocommerce |
| Published | Oct 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown track orders for woocommerce
Be the first to know when new unknown vulnerabilities affecting unknown track orders for woocommerce are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Track Orders for WooCommerce
0 < 1.2.7
References
Credits
Pedro Pinho WPScan