PatchSiren cyber security CVE debrief
CVE-2026-14832 ShopSmart Loyalty for WooCommerce CVE debrief
The ShopSmart Loyalty for WooCommerce WordPress plugin through 1.0.0 has a vulnerability allowing unauthenticated users to retrieve customer loyalty profiles, including name, email, and account balance, if they know the customer's phone number. This vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. The affected product is ShopSmart Loyalty for WooCommerce WordPress plugin version 1.0.0. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations. Evidence from WPScan indicates a vulnerability in ShopSmart Loyalty for WooCommerce WordPress plugin version 1.0.0. Official CVE and NVD records provide additional context.
- Vendor
- ShopSmart Loyalty for WooCommerce
- Product
- WordPress plugin
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-17
- Original CVE updated
- 2026-08-26
- Advisory published
- 2026-08-17
- Advisory updated
- 2026-08-26
Who should care
Administrators and users of the ShopSmart Loyalty for WooCommerce WordPress plugin, as well as security teams monitoring for potential exploitation attempts, should review and update the plugin to version greater than 1.0.0. They should also implement additional authentication and authorization checks for phone-number lookup functionality and monitor for potential exploitation attempts. Affected operators and platforms should prioritize defensive review and compensating controls.
Technical summary
The ShopSmart Loyalty for WooCommerce WordPress plugin through 1.0.0 does not perform any authorization or ownership check on a phone-number lookup exposed to unauthenticated users, allowing anyone who knows a customer's phone number to retrieve that customer's loyalty profile, including name, email, and account balance. This vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. The affected product is ShopSmart Loyalty for WooCommerce WordPress plugin version 1.0.0.
Defensive priority
Medium-priority defensive review recommended due to potential exposure of customer loyalty profiles.
Recommended defensive actions
- Review and update ShopSmart Loyalty for WooCommerce WordPress plugin to version greater than 1.0.0
- Implement additional authentication and authorization checks for phone-number lookup functionality
- Monitor for potential exploitation attempts
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
Evidence from WPScan indicates a vulnerability in ShopSmart Loyalty for WooCommerce WordPress plugin version 1.0.0. Official CVE and NVD records provide additional context. The vulnerability allows unauthenticated users to retrieve customer loyalty profiles, including name, email, and account balance, if they know the customer's phone number. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-14832 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-14832
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-14832 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-14832
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/3b651e19-37f5-468e-8d0b-a82bbe04eaf2/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.