{"api_version":"1","generated_at":"2026-09-16T07:44:01+00:00","cve":"CVE-2026-78474","urls":{"html":"https://cve.report/CVE-2026-78474","api":"https://cve.report/api/cve/CVE-2026-78474.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-78474","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-78474"},"summary":{"title":"Ni WooCommerce Sales Report < 4.2.0 - Unauthenticated Order and Customer Data Disclosure via 'btn_print' Parameter","description":"The Ni WooCommerce Sales Report  WordPress plugin before 4.2.0 does not have any authentication or authorisation checks on one of its report-printing routines, allowing unauthenticated users to retrieve WooCommerce order details and customer contact information, to target an individual order, and to search the store's orders by customer name or email address.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-09-16 06:16:32","updated_at":"2026-09-16 06:16:32"},"problem_types":["CWE-200 Information Exposure"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/9518db93-0cd9-4db5-af9b-5371218c8b50/","name":"https://wpscan.com/vulnerability/9518db93-0cd9-4db5-af9b-5371218c8b50/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-78474","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-78474","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"Ni WooCommerce Sales Report","version":"affected 4.2.0 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"ryan fabella","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Ni WooCommerce Sales Report","vendor":"Unknown","versions":[{"lessThan":"4.2.0","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"ryan fabella"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The Ni WooCommerce Sales Report  WordPress plugin before 4.2.0 does not have any authentication or authorisation checks on one of its report-printing routines, allowing unauthenticated users to retrieve WooCommerce order details and customer contact information, to target an individual order, and to search the store's orders by customer name or email address."}],"problemTypes":[{"descriptions":[{"description":"CWE-200 Information Exposure","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-16T06:00:12.319Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/9518db93-0cd9-4db5-af9b-5371218c8b50/"}],"source":{"discovery":"EXTERNAL"},"title":"Ni WooCommerce Sales Report < 4.2.0 - Unauthenticated Order and Customer Data Disclosure via 'btn_print' Parameter","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-78474","datePublished":"2026-09-16T06:00:12.319Z","dateReserved":"2026-08-24T16:51:40.717Z","dateUpdated":"2026-09-16T06:00:12.319Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-16 06:16:32","lastModifiedDate":"2026-09-16 06:16:32","problem_types":["CWE-200 Information Exposure"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"78474","Ordinal":"1","Title":"Ni WooCommerce Sales Report < 4.2.0 - Unauthenticated Order and ","CVE":"CVE-2026-78474","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"78474","Ordinal":"1","NoteData":"The Ni WooCommerce Sales Report  WordPress plugin before 4.2.0 does not have any authentication or authorisation checks on one of its report-printing routines, allowing unauthenticated users to retrieve WooCommerce order details and customer contact information, to target an individual order, and to search the store's orders by customer name or email address.","Type":"Description","Title":"Ni WooCommerce Sales Report < 4.2.0 - Unauthenticated Order and "}]}}}