CVE-2026-14927: Unknown Fluentcart A New Era Of Ecommerce
Low severity, CVSS 3.7. EPSS: 0.3% chance of exploitation in the next 30 days.
The FluentCart A New Era of eCommerce WordPress plugin before 1.5.3 does not perform any authorization or ownership check before rendering customer order documents keyed on a sequential numeric identifier, allowing unauthenticated visitors to enumerate and disclose customer personal data (names, email addresses, billing and shipping postal addresses, and order details) across the store.
Affected products
- Unknown Fluentcart A New Era Of Ecommerce: before 1.5.3 (fixed in 1.5.3)
Published 2026-07-31. Last modified 2026-08-26.