CVE-2026-61945 MEDIUM

CVE-2026-61945: WordPress WooCommerce Product Stock Alert plugin <= 3.0.6 - Sensitive Data Exposure vulnerability

Vendor Multivendorx
Product WooCommerce Product Stock Alert
Weakness CWE-497
Published July 23, 2026
Last update July 23, 2026

CVSS base score

6.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in MultiVendorX WooCommerce Product Stock Alert allows Retrieve Embedded Sensitive Data. This issue affects WooCommerce Product Stock Alert: from n/a through 3.0.6.

Explanation of Vulnerability in Simple Terms

02Summary

WooCommerce Product Stock Alert versions up to 3.0.6 expose sensitive product and customer data to authenticated users who should not have access. A logged-in user with low privileges can read confidential information including stock levels, pricing, and customer details without authorization. The vulnerability stems from insufficient access controls on data retrieval functions.

What an attacker can do

03Attacker Capabilities

Read sensitive product stock data, pricing, and customer information without proper authorization.

Potential impact on your site

04Site Impact

Customer data and product information may be exposed to unauthorized site users; confidentiality breach.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege user account on the site (e.g., subscriber or customer role).

Key dates

06Disclosure timeline

July 23, 2026 CVE published
July 23, 2026 Record updated

Related vulnerabilities

08Related CVE