By weakness (CWE)
CWE-497: related vulnerabilities
CVEs classified under CWE-497. Understanding the weakness class helps prioritize systemic fixes over one-off patches.
13 published vulnerabilities
- CVE-2026-34891HIGH 7.5
The IDPay Payment Gateway plugin for WooCommerce versions 2.2.5 and earlier contains a flaw that allows attackers to access sensitive payment and transaction data without requiring any authentication. This means an unauthenticated attacker can retrieve confidential information directly over the network—no login credentials or special access needed. The vulnerability is classified as HIGH severity because it exposes sensitive data, though it does not allow attackers to modify data or disrupt service.
- CVE-2026-49056HIGH 7.5
A vulnerability in WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels allows attackers to access sensitive business and customer data without needing to log in. The flaw affects all versions up to and including 4.9.4. An attacker can retrieve information such as invoice details, customer addresses, and order data by making direct requests to the plugin—no authentication or user interaction required. This poses a significant risk to e-commerce sites relying on this plugin, as customer personal information and financial records could be exposed.
- CVE-2026-52694HIGH 7.5
The Signature Add-On for WooCommerce, in versions 2.0 and earlier, exposes sensitive data to unauthenticated users. An attacker can access confidential information without needing credentials or authentication. The vulnerability is network-accessible, requires no special configuration, and can be exploited remotely. This is a significant exposure risk for any WooCommerce installation using this plugin.
- CVE-2026-56060HIGH 7.5
A vulnerability in the 'Print Invoice & Delivery Notes for WooCommerce' plugin (versions up to 7.1.1) allows attackers to access sensitive customer and order information without needing any authentication. The vulnerability exploits insufficient access controls, meaning someone on the internet could potentially retrieve invoices, delivery details, and associated customer data by manipulating requests to the plugin. This is particularly serious for WooCommerce store owners because the exposed data typically includes customer names, addresses, email addresses, phone numbers, and order values.
- CVE-2026-56124HIGH 7.5
phpUploader versions before 2.0.2 have a serious information disclosure flaw that exposes sensitive data about uploaded files to anyone on the internet. Without needing to log in, an attacker can visit any page of a phpUploader application and retrieve the complete database table of uploads, which includes uploader IP addresses, password hashes, filenames, and file checksums. This data is embedded directly in the page's JavaScript, making it trivial to extract.
- CVE-2026-0466MEDIUM 5.5
AMD uProf, a performance profiling tool, contains an access control vulnerability that allows a user with local system access to write data into memory regions normally reserved for the kernel. This weakness could crash the system or render it temporarily unavailable. The vulnerability requires an attacker to already have an account on the target system—it cannot be exploited remotely.
- CVE-2026-49077MEDIUM 5.3
WP eMember, a WordPress membership plugin by Tips and Tricks HQ, contains a vulnerability that exposes sensitive system information to unauthorized users. An attacker without authentication can retrieve embedded sensitive data through network access, potentially learning details about your WordPress installation and membership infrastructure that should remain private. The vulnerability affects all versions through v10.2.2.
- CVE-2026-55726MEDIUM 5.3
Gardyn's Azure Blob Storage container holding device logs is misconfigured to allow public listing without authentication. An attacker can browse and download any device log file stored in this container, potentially exposing sensitive operational and diagnostic information from connected devices.
- CVE-2026-57633MEDIUM 5.3
WCBoost – Products Compare, a WordPress plugin, exposes sensitive information to unauthenticated users in versions 1.1.0 and earlier. An attacker can access data without authentication due to improper access controls, though the data itself is not modified or service availability compromised. This is a localized but meaningful exposure risk for sites relying on this plugin.
- CVE-2026-57753MEDIUM 5.3
The Kit for WooCommerce plugin (formerly ConvertKit) up to version 2.1.5 contains a flaw that allows unauthenticated attackers to access sensitive data. An attacker does not need credentials or user interaction to exploit this issue. The vulnerability exposes information that should remain confidential, though it does not enable modification of data or service disruption. WooCommerce sites running the affected plugin versions are at risk of information disclosure.
- CVE-2026-24618MEDIUM 4.3
CVE-2026-24618 is a medium-severity information disclosure vulnerability affecting HashThemes Hash Elements plugin versions up to 1.5.4. An authenticated attacker can retrieve sensitive system information that should remain hidden from unauthorized users. The vulnerability requires valid user credentials to exploit, limiting its attack surface, but the exposure of system details could facilitate further attacks or reconnaissance.
- CVE-2026-57664MEDIUM 4.3
Bopo, a WooCommerce plugin for building product bundles, contains a flaw in versions 1.1.6 and earlier that allows authenticated users to view sensitive information they shouldn't normally access. The vulnerability requires a valid WordPress login but does not require elevated privileges, and attackers cannot modify or delete data—only read it. This is a moderate-severity issue that primarily affects e-commerce sites using this plugin.
- CVE-2026-44743LOW 3.7
CVE-2026-44743 is a low-severity information disclosure vulnerability in SAP Business Objects that allows unauthorized attackers to leak sensitive data through a specific application endpoint. The vulnerability requires specific conditions to be exploitable and does not affect system integrity or availability—only the confidentiality of information is at risk.