CVE-2026-78474: Ni WooCommerce Sales Report < 4.2.0 - Unauthenticated Order and Customer Data Disclosure via 'btn_print' Parameter
The Ni WooCommerce Sales Report WordPress plugin before 4.2.0 does not have any authentication or authorisation checks on one of its report-printing routines, allowing unauthenticated users to retrieve WooCommerce order details and customer contact information, to target an individual order, and to search the store's orders by customer name or email address.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Stores using Ni WooCommerce Sales Report versions earlier than 4.2.0 are exposed. The affected routine can disclose WooCommerce order details and customer contact information.
Does an attacker need an account or special permissions?
No. The vulnerable report-printing routine lacks authentication and authorization checks, so an unauthenticated user can access it.
What information can be retrieved?
An attacker can target an individual order and retrieve its details and associated customer contact information. They can also search store orders using a customer name or email address.