---
id: CVE-2026-103323
title: >-
  The Integration for Epos Now and WooCommerce WordPress plugin before 4.11.2
  does not perform an authorization check on one of its REST endpoints, allowing
  unauthenticated users to retrieve the site's scheduled background tasks and
  their …
summary: >-
  The Integration for Epos Now and WooCommerce WordPress plugin before 4.11.2
  does not perform an authorization check on one of its REST endpoints, allowing
  unauthenticated users to retrieve the site's scheduled background tasks and
  their …
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-862
product: Integration for Epos Now and WooCommerce
affected:
  - integration_for_epos_now_and_woocommerce >= 4.6.0 < 4.11.2
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T11:17:08.957'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103323'
references:
  - url: 'https://wpscan.com/vulnerability/f1859c64-e1d1-4efc-9f34-15d1f4aa3311/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-07T09:59:46.153137Z'
ingestedAt: '2026-10-07T08:20:03.936Z'
---

## Overview

The Integration for Epos Now and WooCommerce WordPress plugin before 4.11.2 does not perform an authorization check on one of its REST endpoints, allowing unauthenticated users to retrieve the site's scheduled background tasks and their arguments, which include order identifiers and, when WooCommerce's deferred emails feature is enabled, the plaintext passwords of newly registered customers.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
