MEDIUM
imprintnext
CVE published 2026-04-08
CVE-2026-3594
The Riaxe Product Customizer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4 via the '/wp-json/InkXEProductDesignerLite/orders' REST API endpoint. This vulnerability allows unauthenticated access to WooCommerce order data, including customer names, IDs, order IDs, totals, dates, currencies, and statuses. The endpoint is registered with 'permis [truncated]