AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-14314

MEDIUM · CVSS 5.3 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The PeproDev WooCommerce Receipt Uploader plugin for WordPress versions up to 2.8.0 is vulnerable due to inadequate verification of access tokens, enabling unauthenticated attackers to forge tokens and access sensitive image attachments, including payment receipts from other customers. This flaw poses a significant risk to user privacy and data security. WordPress site administrators using this plugin should prioritize addressing this vulnerability to protect customer information.

CVE
CVE-2026-14314
Severity
MEDIUM
CVSS
5.3
EPSS
0.24%
WordPress

Original NVD Description

The PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 does not verify that a requested attachment belongs to the order referenced by its access token, allowing unauthenticated attackers to forge a token and disclose image attachments, including other customers' uploaded payment receipts, that they do not own.