CVE-2026-19073
Gravedad CVSS v3.1:
MEDIA
Tipo:
CWE-200
Revelación de información
Fecha de publicación:
12/08/2026
Última modificación:
12/08/2026
Descripción
*** Pendiente de traducción *** The Order Sync with Zendesk for WooCommerce WordPress plugin before 2.2.3 does not perform any capability check on one of its REST API endpoints, and does not verify that the requester owns the account being queried, allowing unauthenticated attackers to retrieve the order history and purchase totals of any customer whose email address they know or can enumerate.
Impacto
Puntuación base 3.x
5.30
Gravedad 3.x
MEDIA



