VYPR

Track Orders for WooCommerce

by WordPress

CVEs (1)

  • CVE-2026-94275Oct 8, 2026
    risk 0.00cvss —epss —

    The Track Orders for WooCommerce WordPress plugin before 1.2.7 does not verify ownership of an order before returning its billing details, allowing unauthenticated attackers to obtain a customer's name, email address, phone number, postal address and order history by supplying…