CVE-2026-16568 PUBLISHED

ShopApper <= 0.4.62 - Subscriber+ Customer Data Disclosure via IDOR

Assigner: WPScan
Reserved: 22.07.2026 Published: 27.08.2026 Updated: 27.08.2026

The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 does not verify that the requesting user owns the customer profile being queried through one of its REST endpoints, allowing any authenticated user (e.g. a customer/subscriber) to retrieve other users' personal data, including their email address, name, and roles.

Product Status

Vendor Unknown
Product Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce
Versions Default: unknown
  • affected from 0 to 0.4.62 (incl.)

Credits

  • TruongLV1 From FPT Night Wolf finder
  • WPScan coordinator

References

Problem Types

  • CWE-639 Authorization Bypass Through User-Controlled Key CWE