
CVE-2026-14832 The ShopSmart Loyalty for WooCommerce WordPress plugin through 1.0.0 does not perform any authorization or ownership check on a phone-number lookup exposed to unauthe… https://www.cve.org/CVERecord?id=CVE-2026-14832
Post summary
The CVE‑2026‑14832 highlights that the ShopSmart Loyalty WooCommerce plugin fails to perform authorization on a phone‑number lookup, with no evidence of PoC, exploit, active attacks, or patch information.

