CVE-2026-16039: MStore API < 4.21.0 - Subscriber+ Order and Customer PII Disclosure via IDOR
The MStore API WordPress plugin before 4.21.0 does not restrict its vendor-orders endpoint to the caller's own orders, allowing any authenticated user, including Subscribers, to read every WooCommerce order in the store together with each customer's personal information.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress MStore API pluginto a version that resolves this vulnerability.Fixed in 4.21.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16039?
CVE-2026-16039 has a risk rating of 71, indicating it has a high severity level.
How do I fix CVE-2026-16039?
To fix CVE-2026-16039, update the MStore API plugin to version 4.21.0 or later.
What type of data is exposed in CVE-2026-16039?
CVE-2026-16039 exposes customer personal information and order details from WooCommerce.
Who is affected by CVE-2026-16039?
Any authenticated user, including Subscribers, can be affected by CVE-2026-16039 if they have access to the MStore API.
What can attackers do with CVE-2026-16039?
Attackers can exploit CVE-2026-16039 to read and access every WooCommerce order and its associated customer PII.