plugin

Shopsmart Loyalty For Woocommerce Vulnerabilities

1 known security issue reported for the Shopsmart Loyalty For Woocommerce WordPress plugin. Most recent disclosed Aug 14, 2026.

1 medium

Running Shopsmart Loyalty For Woocommerce on your site? Check whether your installed version is affected.

Scan your site free

ShopSmart Loyalty for WooCommerce <= 1.0.0 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure

medium

The ShopSmart Loyalty for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 1.0.0. This is due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 1.0.0
Fix:
No patched version reported
Disclosed:
Aug 14, 2026

CVE-2026-14832 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database