Unrated severityNVD Advisory· Published Oct 7, 2026
CVE-2026-103323
CVE-2026-103323
Description
The Integration for Epos Now and WooCommerce WordPress plugin before 4.11.2 does not perform an authorization check on one of its REST endpoints, allowing unauthenticated users to retrieve the site's scheduled background tasks and their arguments, which include order identifiers and, when WooCommerce's deferred emails feature is enabled, the plaintext passwords of newly registered customers.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <4.11.2
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.