Executive brief
The Kit (formerly ConvertKit) plugin for WooCommerce, which integrates email marketing tools with online stores, contains a security flaw that exposes sensitive information. An unauthorized person could access internal system data or configuration details that are normally restricted. This information could potentially be used to facilitate more complex attacks against the website.
Technical details
A sensitive data exposure vulnerability (CWE-497) exists in the Kit (formerly ConvertKit) for WooCommerce plugin through version 2.1.5. The flaw allows an unauthenticated remote attacker to access sensitive system information that should be restricted to authorized users. The vulnerability stems from improper exposure of information to an unauthorized control sphere. As of the advisory date, no official patch has been released, and users are advised to monitor for updates from the developer.
Affected products
- Nathanbarry Kit (formerly ConvertKit) for WooCommerce <= 2.1.5
Timeline
- 2026-02-09: disclosed: Reported by Nguyen Ba Khanh
- 2026-07-02: advisory: Published by Patchstack and NVD