CVE-2026-16568: ShopApper <= 0.4.62 - Subscriber+ Customer Data Disclosure via IDOR
Published Aug 27, 2026
·Updated
The Mobile App for WooCommerce: ShopApper Mobile App Builder Service for WooCommerce WordPress plugin through 0.4.62 does not verify that the requesting user owns the customer profile being queried through one of its REST endpoints, allowing any authenticated user (e.g. a customer/subscriber) to retrieve other users' personal data, including their email address, name, and roles.
Affected Software
1 affected component
ShopApper Mobile App Builder Service for WooCommerce WordPress plugin<=0.4.62
Event History
Aug 27, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:16 AM
Description
Frequently Asked Questions
1
Who can exploit this issue?
Any authenticated user can exploit it, including users with customer or subscriber-level access. The issue does not require administrative privileges.
2
What information could an attacker obtain?
An attacker can retrieve other users' personal data through the affected REST endpoint, including email addresses, names, and roles.
3
What versions are affected?
The plugin is affected through version 0.4.62.