
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24992 is a sensitive data exposure vulnerability (CWE-201: Insertion of Sensitive Information Into Sent Data) affecting the Advanced WooCommerce Product Sales Reporting plugin by WPFactory for WordPress. The vulnerability allows unauthenticated remote attackers to retrieve embedded sensitive data from affected installations. All versions through 4.1.2 are affected. It was published on February 3, 2026, with a CVSS v3.1 base score of 5.3 (Medium) (Feedly, Patchstack).
The root cause is classified as CWE-201 (Insertion of Sensitive Information Into Sent Data), meaning the plugin inadvertently includes sensitive data in responses sent to unauthenticated users. The attack vector is network-based, requires no authentication, no user interaction, and low attack complexity — making it trivially accessible to any remote attacker. The vulnerability allows retrieval of embedded sensitive data, likely through unauthenticated API endpoints or AJAX handlers that expose sales reporting data without proper access controls (Feedly, Patchstack).
Successful exploitation results in unauthorized disclosure of sensitive WooCommerce sales data, which may include order details, revenue figures, product performance metrics, or other business-sensitive information embedded in plugin responses. The confidentiality impact is rated Low (partial data exposure), with no integrity or availability impact. While lateral movement is unlikely from this vulnerability alone, exposed business data could be leveraged for competitive intelligence, targeted phishing, or further reconnaissance against the affected WordPress site (Feedly).
The vulnerability requires no authentication, no user interaction, and has low attack complexity, making it easily exploitable by any remote attacker. The EPSS score is approximately 0.036% (0.000360), indicating a low but non-zero probability of active exploitation in the near term. No public proof-of-concept exploit code, active in-the-wild exploitation, threat actor attribution, or CISA KEV catalog listing has been reported as of the available data (Feedly).
Users should update the Advanced WooCommerce Product Sales Reporting plugin to a version beyond 4.1.2 that addresses this vulnerability. If no patched version is yet available, the recommended workaround is to deactivate and remove the plugin until a fix is released. Site administrators should also review web server access logs for unexpected unauthenticated requests to plugin-related endpoints and restrict access to sensitive reporting endpoints via firewall rules or .htaccess configurations where possible (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."