AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-19073

MEDIUM · CVSS 5.3 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Order Sync with Zendesk for WooCommerce plugin for WordPress prior to version 2.2.3 is vulnerable due to a lack of capability checks on a REST API endpoint, enabling unauthenticated attackers to access sensitive order history and purchase totals of customers by knowing or enumerating their email addresses. This vulnerability poses a significant risk to customer privacy and data security. WordPress site administrators using this plugin should prioritize immediate updates to mitigate potential data exposure.

CVE
CVE-2026-19073
Severity
MEDIUM
CVSS
5.3
EPSS
0.21%
WordPress

Original NVD Description

The Order Sync with Zendesk for WooCommerce WordPress plugin before 2.2.3 does not perform any capability check on one of its REST API endpoints, and does not verify that the requester owns the account being queried, allowing unauthenticated attackers to retrieve the order history and purchase totals of any customer whose email address they know or can enumerate.