VYPR
Unrated severityNVD Advisory· Published Jul 31, 2026· Updated Jul 31, 2026

FluentCart < 1.5.3 - Unauthenticated Order PII Disclosure via Print Routes

CVE-2026-14927

Description

The FluentCart A New Era of eCommerce WordPress plugin before 1.5.3 does not perform any authorization or ownership check before rendering customer order documents keyed on a sequential numeric identifier, allowing unauthenticated visitors to enumerate and disclose customer personal data (names, email addresses, billing and shipping postal addresses, and order details) across the store.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.