Vulnerabilities / Pinterest for WooCommerce / WPSEC-2026-0662
Pinterest for WooCommerce <= 1.5.1 - Unauthenticated Information Exposure of Password-Protected Products via Rich Pins Metadata
Medium 5.3
CWE-200Fixed in 1.5.2
- ID
- WPSEC-2026-0662
- Plugin
- Pinterest for WooCommerce (pinterest-for-woocommerce)
- Affected
- all versions before 1.5.2
- Remediation
- Update to 1.5.2 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Weakness
- CWE-200
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-08
- Attack surface
- Pinterest for WooCommerce on WPSec AttackSurface
- Fix released
- Published
Description
The Pinterest for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.5.1 due to the plugin not respecting product password protection when generating Rich Pins Open Graph metadata. This makes it possible for unauthenticated attackers to view the description, price, stock status and featured image of password-protected products from the product page's metadata without entering the password. Password-protected products were also included in the product catalog feed sent to Pinterest.
References
- https://wpsec.com/vuln/WPSEC-2026-0662/
- https://plugins.svn.wordpress.org/pinterest-for-woocommerce/tags/1.5.2/
- https://wordpress.org/plugins/pinterest-for-woocommerce/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS