CVE-2026-14314: PeproDev WooCommerce Receipt Uploader <= 2.8.0 - Unauthenticated Image Attachment Disclosure via IDOR
The PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 does not verify that a requested attachment belongs to the order referenced by its access token, allowing unauthenticated attackers to forge a token and disclose image attachments, including other customers' uploaded payment receipts, that they do not own.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14314?
CVE-2026-14314 has a risk score of 62, indicating a significant security concern.
How do I fix CVE-2026-14314?
To fix CVE-2026-14314, update the PeproDev WooCommerce Receipt Uploader plugin to version 2.8.1 or later.
What type of vulnerability is CVE-2026-14314?
CVE-2026-14314 is an unauthenticated image attachment disclosure vulnerability due to insufficient access control.
What can attackers do with CVE-2026-14314?
Attackers can exploit CVE-2026-14314 to access image attachments from other customers' orders.
Who is affected by CVE-2026-14314?
Users of the PeproDev WooCommerce Receipt Uploader plugin version 2.8.0 or earlier on WordPress are affected by CVE-2026-14314.