Junglewise Threat Intelligence

CVE-2026-39586: Ateeq Rafeeq RepairBuddy sensitive data exposure

CVE-2026-39586 · Severity: medium · CVSS 5.3 · Published 2026-04-08

Technologies: Webful Creations RepairBuddy. Vendors: Webful Creations.

Executive brief

RepairBuddy is a WordPress plugin used by computer repair shops to manage customer orders and business operations. A security flaw allows unauthorized individuals to access sensitive information that should be private. This could lead to the exposure of customer data or internal business details, potentially damaging the shop's reputation or facilitating further attacks.

Technical details

The RepairBuddy (computer-repair-shop) plugin for WordPress is vulnerable to CWE-201 (Insertion of Sensitive Information Into Sent Data). This flaw allows an unauthenticated remote attacker to retrieve sensitive information that is inadvertently embedded in data sent by the application. The vulnerability stems from improper data handling within the plugin's components. An attacker can exploit this over the network without any user interaction or special privileges. The issue is resolved in version 4.1133.

Affected products

  • Ateeq Rafeeq (Webful Creations) RepairBuddy (computer-repair-shop) <= 4.1132

Timeline

  • 2026-01-27: other: Vulnerability reported by researcher
  • 2026-02-26: disclosed: Initial disclosure by Patchstack
  • 2026-04-08: advisory: CVE published to NVD
  • 2026-04-13: other: CISA-ADP analysis performed

References

Related threats