What the vulnerability does
01Description
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data.
This issue affects WooCommerce Product Stock Alert: from n/a through 3.0.6.
Explanation of Vulnerability in Simple Terms
02Summary
WooCommerce Product Stock Alert versions up to 3.0.6 expose sensitive product and customer data to authenticated users who should not have access. A logged-in user with low privileges can read confidential information including stock levels, pricing, and customer details without authorization. The vulnerability stems from insufficient access controls on data retrieval functions.
What an attacker can do
03Attacker Capabilities
Read sensitive product stock data, pricing, and customer information without proper authorization.
Potential impact on your site
04Site Impact
Customer data and product information may be exposed to unauthorized site users; confidentiality breach.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege user account on the site (e.g., subscriber or customer role).
Key dates
06Disclosure timeline
July 23, 2026
CVE published
July 23, 2026
Record updated