---
id: CVE-2026-94275
title: >-
  The Track Orders for WooCommerce  WordPress plugin before 1.2.7 does not
  verify ownership of an order before returning its billing details, allowing
  unauthenticated attackers to obtain a customer's name, email address, phone
  number, post…
summary: >-
  The Track Orders for WooCommerce  WordPress plugin before 1.2.7 does not
  verify ownership of an order before returning its billing details, allowing
  unauthenticated attackers to obtain a customer's name, email address, phone
  number, post…
severity: none
cwe:
  - CWE-200
product: Track Orders for WooCommerce
affected:
  - track_orders_for_woocommerce < 1.2.7
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T06:16:47.457'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94275'
references:
  - url: 'https://wpscan.com/vulnerability/0037e6ef-5163-4508-9eef-3173a3951fcc/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-08T07:18:54.844Z'
---

## Overview

The Track Orders for WooCommerce  WordPress plugin before 1.2.7 does not verify ownership of an order before returning its billing details, allowing unauthenticated attackers to obtain a customer's name, email address, phone number, postal address and order history by supplying that customer's email address.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
