{
 "id": "WPSEC-2026-0665",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0665/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0665/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0665/index.md",
 "title": "FoxyShop <= 4.9.7 - Unauthenticated Sensitive Information Exposure via Order Export",
 "description": "The FoxyShop plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.9.7 due to missing capability checks on the transaction and UPS WorldShip export functions, which run on the admin_init hook that WordPress also fires for logged-out requests to admin-ajax.php and admin-post.php. This makes it possible for unauthenticated attackers to export the store's FoxyCart order data, including customer names, email addresses and postal addresses.",
 "plugin": {
  "slug": "foxyshop",
  "name": "FoxyShop",
  "full_name": "FoxyShop",
  "wordpress_org": "https://wordpress.org/plugins/foxyshop/",
  "advisories_url": "https://wpsec.com/vuln/plugin/foxyshop/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/foxyshop"
 },
 "type": "SENSITIVE DATA DISCLOSURE",
 "cwe": [
  "CWE-862"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 7.5,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
  "severity": "High"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "4.9.8",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 4.9.8"
  ]
 },
 "introduced_in": null,
 "fixed_in": "4.9.8",
 "remediation": "Update to 4.9.8 or later.",
 "fix_released": "2026-10-07T15:44:22+00:00",
 "published": "2026-10-08T15:50:18+00:00",
 "updated": "2026-10-07T18:51:17.910905+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0665/",
  "https://plugins.svn.wordpress.org/foxyshop/tags/4.9.8/",
  "https://wordpress.org/plugins/foxyshop/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/foxyshop",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-08"
 }
}