PatchSiren

ShopSmart Loyalty for WooCommerce CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM ShopSmart Loyalty for WooCommerce CVE published 2026-08-17

CVE-2026-14832

The ShopSmart Loyalty for WooCommerce WordPress plugin through 1.0.0 has a vulnerability allowing unauthenticated users to retrieve customer loyalty profiles, including name, email, and account balance, if they know the customer's phone number. This vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. The affected product is ShopSmart Loyalty for WooCommerce WordPress plugin version 1.0.0. Defe [truncated]