ShopSmart Loyalty for WooCommerce <= 1.0.0 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure
mediumThe ShopSmart Loyalty for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 1.0.0. This is due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.0.0
- Fix:
- No patched version reported
- Disclosed:
- Aug 14, 2026