Vulnerabilities / FluentCart A New Era of eCommerce / WPSEC-2026-0717
FluentCart A New Era of eCommerce <= 1.7.0 - Unauthenticated Insecure Direct Object Reference to Sensitive Information Exposure via 'order_id' Parameter
Medium 5.3
CWE-639Fixed in 1.7.1
- ID
- WPSEC-2026-0717
- Plugin
- FluentCart A New Era of eCommerce – Faster, Lighter, and Simpler (fluent-cart)
- Affected
- all versions before 1.7.1
- Remediation
- Update to 1.7.1 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Weakness
- CWE-639
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-10
- Attack surface
- FluentCart A New Era of eCommerce on WPSec AttackSurface
- Fix released
- Published
Description
The FluentCart A New Era of eCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.7.0 via the 'order_id' parameter of the checkout place-order flow. This is due to the plugin accepting a user-controlled order ID that is then used to load the saved addresses of that order without verifying it belongs to the current cart. This makes it possible for unauthenticated attackers to pull other customers' billing and shipping address data into their own checkout and order.
References
- https://wpsec.com/vuln/WPSEC-2026-0717/
- https://plugins.svn.wordpress.org/fluent-cart/tags/1.7.1/
- https://wordpress.org/plugins/fluent-cart/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS