PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-14832 ShopSmart Loyalty for WooCommerce CVE debrief

The ShopSmart Loyalty for WooCommerce WordPress plugin through 1.0.0 has a vulnerability allowing unauthenticated users to retrieve customer loyalty profiles, including name, email, and account balance, if they know the customer's phone number. This vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. The affected product is ShopSmart Loyalty for WooCommerce WordPress plugin version 1.0.0. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations. Evidence from WPScan indicates a vulnerability in ShopSmart Loyalty for WooCommerce WordPress plugin version 1.0.0. Official CVE and NVD records provide additional context.

Vendor
ShopSmart Loyalty for WooCommerce
Product
WordPress plugin
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-17
Original CVE updated
2026-08-26
Advisory published
2026-08-17
Advisory updated
2026-08-26

Who should care

Administrators and users of the ShopSmart Loyalty for WooCommerce WordPress plugin, as well as security teams monitoring for potential exploitation attempts, should review and update the plugin to version greater than 1.0.0. They should also implement additional authentication and authorization checks for phone-number lookup functionality and monitor for potential exploitation attempts. Affected operators and platforms should prioritize defensive review and compensating controls.

Technical summary

The ShopSmart Loyalty for WooCommerce WordPress plugin through 1.0.0 does not perform any authorization or ownership check on a phone-number lookup exposed to unauthenticated users, allowing anyone who knows a customer's phone number to retrieve that customer's loyalty profile, including name, email, and account balance. This vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. The affected product is ShopSmart Loyalty for WooCommerce WordPress plugin version 1.0.0.

Defensive priority

Medium-priority defensive review recommended due to potential exposure of customer loyalty profiles.

Recommended defensive actions

  • Review and update ShopSmart Loyalty for WooCommerce WordPress plugin to version greater than 1.0.0
  • Implement additional authentication and authorization checks for phone-number lookup functionality
  • Monitor for potential exploitation attempts
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

Evidence from WPScan indicates a vulnerability in ShopSmart Loyalty for WooCommerce WordPress plugin version 1.0.0. Official CVE and NVD records provide additional context. The vulnerability allows unauthenticated users to retrieve customer loyalty profiles, including name, email, and account balance, if they know the customer's phone number. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-14832 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-14832

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-14832 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-14832

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.