CVE-2026-14927: Unknown Fluentcart A New Era Of Ecommerce

Low severity, CVSS 3.7. EPSS: 0.3% chance of exploitation in the next 30 days.

The FluentCart A New Era of eCommerce WordPress plugin before 1.5.3 does not perform any authorization or ownership check before rendering customer order documents keyed on a sequential numeric identifier, allowing unauthenticated visitors to enumerate and disclose customer personal data (names, email addresses, billing and shipping postal addresses, and order details) across the store.

Affected products

  • Unknown Fluentcart A New Era Of Ecommerce: before 1.5.3 (fixed in 1.5.3)

Published 2026-07-31. Last modified 2026-08-26.