high
CVE-2026-14832
ShopSmart Loyalty for WooCommerce unauthenticated customer-record disclosure - shopsmart_check_phone returns a loyalty profile to anyone who supplies a phone number, with no ownership or capability check
- Severity
- high
- Affected product
- shopsmart-loyalty-for-woocommerce
- Affected versions
- shopsmart-loyalty-for-woocommerce ≤ 1.0.0
- Fixed in
- shopsmart-loyalty-for-woocommerce no fixed release yet
- Added to NewScan
- 2026-08-17
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints shopsmart-loyalty-for-woocommerce from its response and reports this CVE when the detected version falls inside the affected range below.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →