What is CVE-2026-16039?
CVE-2026-16039 affects the MStore API WordPress plugin before version 4.21.0, exposing a vulnerability in its 'vendor-orders' endpoint. This flaw allows any authenticated user, including Subscribers, to read all WooCommerce orders and the associated customer personal information. Administrators should immediately update the plugin to version 4.21.0 or later to mitigate the risk.
Azərbaycanca: CVE-2026-16039, MStore API WordPress plaginini 4.21.0 versiyasından əvvəl təsir edən boşluqdur. Bu boşluq autentifikasiyalı istənilən istifadəçiyə (Subscriber daxil) 'vendor-orders' endpoint-i vasitəsilə mağazanın bütün WooCommerce sifarişlərini və müştərilərin şəxsi məlumatlarını oxumağa imkan verir. Təhlükəsizlik üçün plagini dərhal 4.21.0 və ya daha yuxarı versiyaya yeniləmək lazımdır.
Related CVEs
link basis: same weakness class CWE-862
FAQ1
Which WordPress plugin vulnerability allows any authenticated user to read WooCommerce orders?
The vulnerability CVE-2026-16039 in MStore API plugin versions before 4.21.0 allows any authenticated user, including Subscribers, to read all WooCommerce orders and associated customer personal information through the 'vendor-orders' endpoint.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.