CVE-2026-14927 PUBLISHED

FluentCart < 1.5.3 - Unauthenticated Order PII Disclosure via Print Routes

Assigner: WPScan
Reserved: 07.07.2026 Published: 31.07.2026 Updated: 31.07.2026

The FluentCart A New Era of eCommerce WordPress plugin before 1.5.3 does not perform any authorization or ownership check before rendering customer order documents keyed on a sequential numeric identifier, allowing unauthenticated visitors to enumerate and disclose customer personal data (names, email addresses, billing and shipping postal addresses, and order details) across the store.

Product Status

Vendor Unknown
Product FluentCart A New Era of eCommerce
Versions Default: unaffected
  • affected from 0 to 1.5.3 (excl.)

Credits

  • Diogo Pinto finder
  • WPScan coordinator

References

Problem Types

  • CWE-639 Authorization Bypass Through User-Controlled Key CWE