---
id: CVE-2026-78474
title: >-
  The Ni WooCommerce Sales Report  WordPress plugin before 4.2.0 does not have
  any authentication or authorisation checks on one of its report-printing
  routines, allowing unauthenticated users to retrieve WooCommerce order details
  and cust…
summary: >-
  The Ni WooCommerce Sales Report  WordPress plugin before 4.2.0 does not have
  any authentication or authorisation checks on one of its report-printing
  routines, allowing unauthenticated users to retrieve WooCommerce order details
  and cust…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
product: Ni WooCommerce Sales Report
affected:
  - ni_woocommerce_sales_report < 4.2.0
published: '2026-09-16'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T13:16:47.957'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-78474'
references:
  - url: 'https://wpscan.com/vulnerability/9518db93-0cd9-4db5-af9b-5371218c8b50/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-17T12:20:54.520442Z'
epss: 0.00377
epssPercentile: 0.31588
ingestedAt: '2026-09-16T06:51:06.247Z'
---

## Overview

The Ni WooCommerce Sales Report  WordPress plugin before 4.2.0 does not have any authentication or authorisation checks on one of its report-printing routines, allowing unauthenticated users to retrieve WooCommerce order details and customer contact information, to target an individual order, and to search the store's orders by customer name or email address.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
