PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-3594 imprintnext CVE debrief

The Riaxe Product Customizer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4 via the '/wp-json/InkXEProductDesignerLite/orders' REST API endpoint. This vulnerability allows unauthenticated access to WooCommerce order data, including customer names, IDs, order IDs, totals, dates, currencies, and statuses. The endpoint is registered with 'permission_callback' set to '__return_true', meaning no authentication or authorization checks are performed. This makes it possible for unauthenticated attackers to extract sensitive customer and order information from the WooCommerce store. Affected administrators should prioritize updating the plugin and restricting access to the vulnerable endpoint.

Vendor
imprintnext
Product
Riaxe Product Customizer
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-08
Original CVE updated
2026-07-24
Advisory published
2026-04-08
Advisory updated
2026-07-24

Who should care

Administrators of WordPress installations using the Riaxe Product Customizer plugin, especially those handling customer data and orders, should be aware of this vulnerability. They should review their installations for exposure, update the plugin to a version beyond 2.4, and implement additional authentication and authorization checks for sensitive data access. Security teams and vulnerability management teams should also be aware of this vulnerability and prioritize remediation efforts.

Technical summary

The Riaxe Product Customizer plugin for WordPress is vulnerable to Sensitive Information Exposure due to an unauthenticated REST API endpoint. The '/wp-json/InkXEProductDesignerLite/orders' endpoint, registered with 'permission_callback' set to '__return_true', allows unauthenticated access to WooCommerce order data, including customer names, IDs, order IDs, totals, dates, currencies, and statuses. This vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. The endpoint queries WooCommerce order data from the database and returns it to the requester without any authentication or authorization checks.

Defensive priority

Medium priority due to the potential for data exposure.

Recommended defensive actions

  • Update the Riaxe Product Customizer plugin to a version beyond 2.4.
  • Restrict access to the '/wp-json/InkXEProductDesignerLite/orders' endpoint.
  • Monitor for suspicious API requests.
  • Review and limit the data exposed through API endpoints.
  • Implement additional authentication and authorization checks for sensitive data access.
  • Perform a thorough review of WooCommerce order data exposure.
  • Track exceptions and retest remediated assets.

Evidence notes

The vulnerability was reported by [email protected]. The CVE record was published on 2026-04-08T07:16:21.620Z and last modified on 2026-07-24T21:10:00.143Z. The Riaxe Product Customizer plugin for WordPress is vulnerable to Sensitive Information Exposure due to an unauthenticated REST API endpoint. The endpoint queries WooCommerce order data from the database and returns it to the requester, including customer first and last names, customer IDs, order IDs, order totals, order dates, currencies, and order statuses. Evidence limits suggest that defenders verify WooCommerce order data exposure and review API endpoint access controls.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-3594 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-3594

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-3594 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-3594

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/riaxe-product-customizer/tags/2.4/riaxe-product-designer.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/riaxe-product-customizer/tags/2.4/riaxe-product-designer.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/riaxe-product-customizer/tags/2.4/riaxe-product-designer.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/riaxe-product-customizer/tags/2.4/riaxe-product-designer.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/riaxe-product-customizer/trunk/riaxe-product-designer.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/riaxe-product-customizer/trunk/riaxe-product-designer.php

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://plugins.trac.wordpress.org/browser/riaxe-product-customizer/trunk/riaxe-product-designer.php

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.