Medium severity5.3NVD Advisory· Published Aug 17, 2026· Updated Aug 26, 2026
CVE-2026-14832
CVE-2026-14832
Description
The ShopSmart Loyalty for WooCommerce WordPress plugin through 1.0.0 does not perform any authorization or ownership check on a phone-number lookup exposed to unauthenticated users, allowing anyone who knows a customer's phone number to retrieve that customer's loyalty profile, including name, email, and account balance.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<=1.0.0+ 1 more
- (no CPE)range: <=1.0.0
- (no CPE)range: <=1.0.0
Patches
Vulnerability mechanics
References
1News mentions
2- Wordfence Intelligence Weekly WordPress Vulnerability Report (August 10, 2026 to August 16, 2026)Wordfence Blog · Aug 21, 2026
- WordPress Plugins: 25 Vulnerabilities Disclosed in Single Batch, Including Critical FlawsVypr Intelligence · Aug 17, 2026