FluentCart A New Era of eCommerce <= 1.7.0 - Unauthenticated Insecure Direct Object Reference to Sensitive Information Exposure via 'order_id' Parameter

Medium 5.3 CWE-639Fixed in 1.7.1
ID
WPSEC-2026-0717
Plugin
FluentCart A New Era of eCommerce – Faster, Lighter, and Simpler (fluent-cart)
Affected
all versions before 1.7.1
Remediation
Update to 1.7.1 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness
CWE-639
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-10
Attack surface
FluentCart A New Era of eCommerce on WPSec AttackSurface
Fix released
Published

Description

The FluentCart A New Era of eCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.7.0 via the 'order_id' parameter of the checkout place-order flow. This is due to the plugin accepting a user-controlled order ID that is then used to load the saved addresses of that order without verifying it belongs to the current cart. This makes it possible for unauthenticated attackers to pull other customers' billing and shipping address data into their own checkout and order.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0