Junglewise Threat Intelligence

CVE-2026-52694: WP E-Signature Signature Add-On for WooCommerce sensitive data exposure

CVE-2026-52694 · Severity: high · CVSS 7.5 · Published 2026-06-15

Executive brief

The Signature Add-On for WooCommerce, a plugin used to collect digital signatures during the checkout process, contains a security flaw that allows unauthorized individuals to access sensitive information. This could lead to the exposure of customer data or internal system details that are normally protected. An attacker could exploit this remotely without needing any login credentials, potentially compromising customer privacy or gaining information to launch further attacks.

Technical details

The Signature Add-On for WooCommerce plugin (<= 2.0) suffers from an unauthenticated sensitive data exposure vulnerability, classified as CWE-497 (Exposure of Sensitive System Information to an Unauthorized Control Sphere). The flaw allows a remote attacker to access sensitive information without authentication by interacting with affected plugin components. This exposure can provide attackers with data necessary to facilitate more complex attacks against the WordPress environment. The issue is resolved in version 2.0.1. Patchstack notes that due to the nature of the vulnerability, traditional virtual patching may not be applicable, making the software update critical.

Affected products

  • WP E-Signature Signature Add-On for WooCommerce <= 2.0

Timeline

  • 2026-05-23: other: Vulnerability reported by researcher Averon Averenkov
  • 2026-06-10: advisory: Patchstack published advisory and assigned PSID eb06557660d5
  • 2026-06-15: disclosed: CVE-2026-52694 published to NVD
  • 2026-06-10: patched: Version 2.0.1 released to address the vulnerability

References