What is CVE-2026-14314?
The PeproDev WooCommerce Receipt Uploader WordPress plugin up to version 2.8.0 fails to verify that an attachment belongs to the order associated with an access token. This allows unauthenticated attackers to forge a token and disclose other customers' uploaded payment receipt images. Immediate update or temporary deactivation is recommended.
Azərbaycanca: PeproDev WooCommerce Receipt Uploader plaqini 2.8.0 versiyasına qədər WordPress üçün istifadə olunan bir əlavədir. Bu boşluq autentifikasiya olunmamış hücumçulara token yaratmağa və müştərilərin yüklədiyi ödəniş qəbzi şəkillərini sızdırmağa imkan verir. Təcili olaraq plaqini yeniləmək və ya müvəqqəti olaraq söndürmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ1
What does the CVE-2026-14314 vulnerability in the PeproDev WooCommerce Receipt Uploader plugin allow?
It allows unauthenticated attackers to forge a token and disclose other customers' uploaded payment receipt images.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.