CVE-2026-24992: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-24992 is a sensitive data exposure vulnerability (CWE-201: Insertion of Sensitive Information Into Sent Data) affecting the Advanced WooCommerce Product Sales Reporting plugin by WPFactory for WordPress. The vulnerability allows unauthenticated remote attackers to retrieve embedded sensitive data from affected installations. All versions through 4.1.2 are affected. It was published on February 3, 2026, with a CVSS v3.1 base score of 5.3 (Medium) (Feedly, Patchstack).

Technical details

The root cause is classified as CWE-201 (Insertion of Sensitive Information Into Sent Data), meaning the plugin inadvertently includes sensitive data in responses sent to unauthenticated users. The attack vector is network-based, requires no authentication, no user interaction, and low attack complexity — making it trivially accessible to any remote attacker. The vulnerability allows retrieval of embedded sensitive data, likely through unauthenticated API endpoints or AJAX handlers that expose sales reporting data without proper access controls (Feedly, Patchstack).

Impact

Successful exploitation results in unauthorized disclosure of sensitive WooCommerce sales data, which may include order details, revenue figures, product performance metrics, or other business-sensitive information embedded in plugin responses. The confidentiality impact is rated Low (partial data exposure), with no integrity or availability impact. While lateral movement is unlikely from this vulnerability alone, exposed business data could be leveraged for competitive intelligence, targeted phishing, or further reconnaissance against the affected WordPress site (Feedly).

Exploitability

The vulnerability requires no authentication, no user interaction, and has low attack complexity, making it easily exploitable by any remote attacker. The EPSS score is approximately 0.036% (0.000360), indicating a low but non-zero probability of active exploitation in the near term. No public proof-of-concept exploit code, active in-the-wild exploitation, threat actor attribution, or CISA KEV catalog listing has been reported as of the available data (Feedly).

Mitigation and workarounds

Users should update the Advanced WooCommerce Product Sales Reporting plugin to a version beyond 4.1.2 that addresses this vulnerability. If no patched version is yet available, the recommended workaround is to deactivate and remove the plugin until a fix is released. Site administrators should also review web server access logs for unexpected unauthenticated requests to plugin-related endpoints and restrict access to sensitive reporting endpoints via firewall rules or .htaccess configurations where possible (Patchstack).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management