MEDIUM
ShopSmart Loyalty for WooCommerce
CVE published 2026-08-17
CVE-2026-14832
The ShopSmart Loyalty for WooCommerce WordPress plugin through 1.0.0 has a vulnerability allowing unauthenticated users to retrieve customer loyalty profiles, including name, email, and account balance, if they know the customer's phone number. This vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. The affected product is ShopSmart Loyalty for WooCommerce WordPress plugin version 1.0.0. Defe [truncated]