CyberRota Analysis
AI-GeneratedThe ShopSmart Loyalty for WooCommerce WordPress plugin prior to version 1.0.0 is vulnerable as it lacks proper authorization checks on phone-number lookups, enabling unauthenticated users to access sensitive customer information, including names, emails, and account balances. This vulnerability poses a significant risk to customer privacy and data security. WordPress site administrators using this plugin should prioritize immediate updates to mitigate potential data breaches.
Original NVD Description
The ShopSmart Loyalty for WooCommerce WordPress plugin through 1.0.0 does not perform any authorization or ownership check on a phone-number lookup exposed to unauthenticated users, allowing anyone who knows a customer's phone number to retrieve that customer's loyalty profile, including name, email, and account balance.