Ni WooCommerce Sales Report < 4.2.0 - Unauthenticated Order and Customer Data Disclosure via 'btn_print' Parameter
Summary
| CVE | CVE-2026-78474 |
|---|---|
| State | PUBLISHED |
| Assigner | WPScan |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-16 06:16:32 UTC |
| Updated | 2026-09-16 06:16:32 UTC |
| Description | The Ni WooCommerce Sales Report WordPress plugin before 4.2.0 does not have any authentication or authorisation checks on one of its report-printing routines, allowing unauthenticated users to retrieve WooCommerce order details and customer contact information, to target an individual order, and to search the store's orders by customer name or email address. |
Risk And Classification
Problem Types: CWE-200 Information Exposure
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Unknown | Ni WooCommerce Sales Report | affected 4.2.0 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| wpscan.com/vulnerability/9518db93-0cd9-4db5-af9b-5371218c8b50 | [email protected] | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: ryan fabella (en)
CNA: WPScan (en)
There are currently no legacy QID mappings associated with this CVE.