# Pinterest for WooCommerce <= 1.5.1 - Unauthenticated Information Exposure of Password-Protected Products via Rich Pins Metadata

- **ID:** WPSEC-2026-0662
- **Plugin:** Pinterest for WooCommerce (`pinterest-for-woocommerce`), https://wordpress.org/plugins/pinterest-for-woocommerce/
- **Affected versions:** all versions before 1.5.2
- **Fixed in:** 1.5.2 (Update to 1.5.2 or later.)
- **Severity:** Medium 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
- **Weakness:** CWE-200
- **Usage among sites WPSec scans:** plugin Medium, affected versions Medium (as of 2026-10-08)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/pinterest-for-woocommerce
- **Fix released:** 2026-10-07
- **Published:** 2026-10-08
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0662/

## Description

The Pinterest for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.5.1 due to the plugin not respecting product password protection when generating Rich Pins Open Graph metadata. This makes it possible for unauthenticated attackers to view the description, price, stock status and featured image of password-protected products from the product page's metadata without entering the password. Password-protected products were also included in the product catalog feed sent to Pinterest.

## References

- https://wpsec.com/vuln/WPSEC-2026-0662/
- https://plugins.svn.wordpress.org/pinterest-for-woocommerce/tags/1.5.2/
- https://wordpress.org/plugins/pinterest-for-woocommerce/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0662/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
