{"api_version":"1","generated_at":"2026-09-09T09:11:53+00:00","cve":"CVE-2026-80339","urls":{"html":"https://cve.report/CVE-2026-80339","api":"https://cve.report/api/cve/CVE-2026-80339.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-80339","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-80339"},"summary":{"title":"Payment Plugins for Stripe WooCommerce < 4.0.12 - Unauthenticated Customer PII Disclosure via order-pay","description":"The Payment Plugins for Stripe WooCommerce WordPress plugin before 4.0.12 does not validate the order key before adding order data to the JavaScript configuration it outputs on the front end, allowing unauthenticated users to obtain the billing details of any order, together with the secret that gates access to it, by iterating sequential order identifiers.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-09-09 06:17:16","updated_at":"2026-09-09 06:17:16"},"problem_types":["CWE-200 Information Exposure"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/736bc501-6e70-409c-bf0d-1b4ef59e5430/","name":"https://wpscan.com/vulnerability/736bc501-6e70-409c-bf0d-1b4ef59e5430/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-80339","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80339","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"Payment Plugins for Stripe WooCommerce","version":"affected 4.0.0 4.0.12 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"m1w34p0n","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Payment Plugins for Stripe WooCommerce","vendor":"Unknown","versions":[{"lessThan":"4.0.12","status":"affected","version":"4.0.0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"m1w34p0n"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The Payment Plugins for Stripe WooCommerce WordPress plugin before 4.0.12 does not validate the order key before adding order data to the JavaScript configuration it outputs on the front end, allowing unauthenticated users to obtain the billing details of any order, together with the secret that gates access to it, by iterating sequential order identifiers."}],"problemTypes":[{"descriptions":[{"description":"CWE-200 Information Exposure","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-09T06:00:05.621Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/736bc501-6e70-409c-bf0d-1b4ef59e5430/"}],"source":{"discovery":"EXTERNAL"},"title":"Payment Plugins for Stripe WooCommerce < 4.0.12 - Unauthenticated Customer PII Disclosure via order-pay","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-80339","datePublished":"2026-09-09T06:00:05.621Z","dateReserved":"2026-08-26T09:19:33.772Z","dateUpdated":"2026-09-09T06:00:05.621Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-09 06:17:16","lastModifiedDate":"2026-09-09 06:17:16","problem_types":["CWE-200 Information Exposure"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"80339","Ordinal":"1","Title":"Payment Plugins for Stripe WooCommerce < 4.0.12 - Unauthenticate","CVE":"CVE-2026-80339","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"80339","Ordinal":"1","NoteData":"The Payment Plugins for Stripe WooCommerce WordPress plugin before 4.0.12 does not validate the order key before adding order data to the JavaScript configuration it outputs on the front end, allowing unauthenticated users to obtain the billing details of any order, together with the secret that gates access to it, by iterating sequential order identifiers.","Type":"Description","Title":"Payment Plugins for Stripe WooCommerce < 4.0.12 - Unauthenticate"}]}}}