CVE-2026-28169 MEDIUM

CVE-2026-28169: WordPress YITH WooCommerce Zoom Magnifier plugin <= 2.52.0 - Sensitive Data Exposure vulnerability

Vendor Yithemes
Product YITH WooCommerce Zoom Magnifier
Weakness CWE-497
Published August 6, 2026
Last update August 6, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions.

Explanation of Vulnerability in Simple Terms

02Summary

YITH WooCommerce Zoom Magnifier versions up to 2.52.0 expose sensitive system information to unauthorized users. An attacker can read details about the site's configuration or environment without authentication. This information could be used to plan further attacks. Update to a version newer than 2.52.0.

What an attacker can do

03Attacker Capabilities

Read sensitive system information about the site's configuration or environment.

Potential impact on your site

04Site Impact

Site configuration details may be exposed to attackers, potentially aiding reconnaissance for further attacks.

Conditions required to exploit

05Prerequisites

No authentication or user interaction required; attacker needs only network access to the site.

Key dates

06Disclosure timeline

August 6, 2026 CVE published
August 6, 2026 Record updated

Related vulnerabilities

08Related CVE