Executive brief
RepairBuddy is a WordPress plugin used by computer repair shops to manage customer orders and business operations. A security flaw allows unauthorized individuals to access sensitive information that should be private. This could lead to the exposure of customer data or internal business details, potentially damaging the shop's reputation or facilitating further attacks.
Technical details
The RepairBuddy (computer-repair-shop) plugin for WordPress is vulnerable to CWE-201 (Insertion of Sensitive Information Into Sent Data). This flaw allows an unauthenticated remote attacker to retrieve sensitive information that is inadvertently embedded in data sent by the application. The vulnerability stems from improper data handling within the plugin's components. An attacker can exploit this over the network without any user interaction or special privileges. The issue is resolved in version 4.1133.
Affected products
- Ateeq Rafeeq (Webful Creations) RepairBuddy (computer-repair-shop) <= 4.1132
Timeline
- 2026-01-27: other: Vulnerability reported by researcher
- 2026-02-26: disclosed: Initial disclosure by Patchstack
- 2026-04-08: advisory: CVE published to NVD
- 2026-04-13: other: CISA-ADP analysis performed