{
 "id": "WPSEC-2026-0717",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0717/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0717/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0717/index.md",
 "title": "FluentCart A New Era of eCommerce <= 1.7.0 - Unauthenticated Insecure Direct Object Reference to Sensitive Information Exposure via 'order_id' Parameter",
 "description": "The FluentCart A New Era of eCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.7.0 via the 'order_id' parameter of the checkout place-order flow. This is due to the plugin accepting a user-controlled order ID that is then used to load the saved addresses of that order without verifying it belongs to the current cart. This makes it possible for unauthenticated attackers to pull other customers' billing and shipping address data into their own checkout and order.",
 "plugin": {
  "slug": "fluent-cart",
  "name": "FluentCart A New Era of eCommerce",
  "full_name": "FluentCart A New Era of eCommerce – Faster, Lighter, and Simpler",
  "wordpress_org": "https://wordpress.org/plugins/fluent-cart/",
  "advisories_url": "https://wpsec.com/vuln/plugin/fluent-cart/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/fluent-cart"
 },
 "type": "IDOR",
 "cwe": [
  "CWE-639"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.3,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "1.7.1",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 1.7.1"
  ]
 },
 "introduced_in": null,
 "fixed_in": "1.7.1",
 "remediation": "Update to 1.7.1 or later.",
 "fix_released": "2026-10-08T14:52:13+00:00",
 "published": "2026-10-10T15:41:27+00:00",
 "updated": "2026-10-10T14:53:31.146061+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0717/",
  "https://plugins.svn.wordpress.org/fluent-cart/tags/1.7.1/",
  "https://wordpress.org/plugins/fluent-cart/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/fluent-cart",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-10"
 }
}