Pinterest for WooCommerce <= 1.5.1 - Unauthenticated Information Exposure of Password-Protected Products via Rich Pins Metadata

Medium 5.3 CWE-200Fixed in 1.5.2
ID
WPSEC-2026-0662
Plugin
Pinterest for WooCommerce (pinterest-for-woocommerce)
Affected
all versions before 1.5.2
Remediation
Update to 1.5.2 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness
CWE-200
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-08
Attack surface
Pinterest for WooCommerce on WPSec AttackSurface
Fix released
Published

Description

The Pinterest for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.5.1 due to the plugin not respecting product password protection when generating Rich Pins Open Graph metadata. This makes it possible for unauthenticated attackers to view the description, price, stock status and featured image of password-protected products from the product page's metadata without entering the password. Password-protected products were also included in the product catalog feed sent to Pinterest.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0