AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-16039

MEDIUM · CVSS 6.5 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The MStore API WordPress plugin prior to version 4.21.0 is vulnerable as it fails to restrict access to the vendor-orders endpoint, allowing any authenticated user, including those with minimal permissions like Subscribers, to access all WooCommerce orders and associated customer personal information. This exposure can lead to significant data privacy breaches and unauthorized access to sensitive customer data. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential risks.

CVE
CVE-2026-16039
Severity
MEDIUM
CVSS
6.5
EPSS
0.20%
WordPress

Original NVD Description

The MStore API WordPress plugin before 4.21.0 does not restrict its vendor-orders endpoint to the caller's own orders, allowing any authenticated user, including Subscribers, to read every WooCommerce order in the store together with each customer's personal information.