Executive brief
The Ebook Store plugin for WordPress, which allows site owners to sell digital books, contains a security flaw that exposes sensitive information to unauthorized users. An attacker can access data that should be private without needing to log in or have any special permissions. This could lead to the exposure of customer details or internal system information, potentially facilitating further attacks on the website.
Technical details
The Ebook Store plugin for WordPress is vulnerable to sensitive data exposure due to missing authorization (CWE-862) in versions up to and including 6.19. A remote, unauthenticated attacker can exploit this flaw by sending crafted network requests to the affected component to view sensitive information that should be restricted. The vulnerability has a CVSS score of 7.5, reflecting high confidentiality impact with no requirement for user interaction or privileges. The issue is resolved in version 6.20.
Affected products
- motov.net Ebook Store <= 6.19
Timeline
- 2026-02-19: other: Reported by researcher hivesec
- 2026-07-23: advisory: Patchstack advisory published
- 2026-07-27: disclosed: CVE published to NVD dataset
- 2026-07-27: patched: Version 6.20 released to address the vulnerability