# FluentCart A New Era of eCommerce <= 1.7.0 - Unauthenticated Insecure Direct Object Reference to Sensitive Information Exposure via 'order_id' Parameter

- **ID:** WPSEC-2026-0717
- **Plugin:** FluentCart A New Era of eCommerce – Faster, Lighter, and Simpler (`fluent-cart`), https://wordpress.org/plugins/fluent-cart/
- **Affected versions:** all versions before 1.7.1
- **Fixed in:** 1.7.1 (Update to 1.7.1 or later.)
- **Severity:** Medium 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
- **Weakness:** CWE-639
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-10)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/fluent-cart
- **Fix released:** 2026-10-08
- **Published:** 2026-10-10
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0717/

## Description

The FluentCart A New Era of eCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.7.0 via the 'order_id' parameter of the checkout place-order flow. This is due to the plugin accepting a user-controlled order ID that is then used to load the saved addresses of that order without verifying it belongs to the current cart. This makes it possible for unauthenticated attackers to pull other customers' billing and shipping address data into their own checkout and order.

## References

- https://wpsec.com/vuln/WPSEC-2026-0717/
- https://plugins.svn.wordpress.org/fluent-cart/tags/1.7.1/
- https://wordpress.org/plugins/fluent-cart/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0717/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
