WordPress Plugin Vulnerabilities

FluentCart < 1.5.3 - Unauthenticated Order PII Disclosure via Print Routes

Description

The plugin does not perform any authorization or ownership check before rendering customer order documents keyed on a sequential numeric identifier, allowing unauthenticated visitors to enumerate and disclose customer personal data (names, email addresses, billing and shipping postal addresses, and order details) across the store.

Proof of Concept

Affects Plugins

Fixed in 1.5.3

References

Classification

Type
IDOR
CWE
CVSS

Miscellaneous

Original Researcher
Diogo Pinto
Submitter
Diogo Pinto
Verified
Yes

Timeline

Publicly Published
2026-07-13 (about 9 days ago)
Added
2026-07-13 (about 8 days ago)
Last Updated
2026-07-13 (about 8 days ago)

Other