What is CVE-2026-14927?
CVE-2026-14927 is a vulnerability in the FluentCart WordPress plugin before version 1.5.3 where customer order documents are rendered based on sequential numeric identifiers without authorization or ownership checks. This allows unauthenticated visitors to enumerate and disclose customer personal data, including names and emails. Updating to the latest version is strongly recommended.
Azərbaycanca: CVE-2026-14927 FluentCart WordPress plaginində 1.5.3-dən əvvəlki versiyalarda sıra ilə gedən nömrələr vasitəsilə müştəri sifariş sənədlərinə icazəsiz girişi təmin edən boşluqdur. Bu, autentifikasiya olunmamış ziyarətçilərə müştərilərin şəxsi məlumatlarını (adlar, e-poçtlar) ifşa etməyə imkan yaradır. Plaginin ən son versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the FluentCart WordPress plugin are affected by CVE-2026-14927?
Versions of the FluentCart plugin before 1.5.3 are affected.
What customer data can unauthenticated visitors access through CVE-2026-14927?
This vulnerability allows unauthenticated visitors to access customer personal data, including names and emails.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.