Executive brief
The Ni WooCommerce Sales Report plugin for WordPress has an authentication bypass flaw that allows unauthenticated attackers to access sensitive customer and order data. An attacker can retrieve detailed order information, customer contact details, search orders by name or email, and target specific orders without any login credentials. This exposes confidential business and customer data to unauthorized disclosure.
Technical details
The plugin lacks authentication and authorization checks in its report-printing routine, specifically the 'btn_print' parameter handling. This is a sensitive data disclosure vulnerability (CWE-200) affecting versions before 4.2.0. The vulnerability is network-accessible and requires no authentication, user interaction, or special privileges; an unauthenticated attacker can craft requests to the vulnerable endpoint to retrieve WooCommerce order details and customer contact information. The vulnerability was publicly disclosed on 2026-09-14 with a proof-of-concept scheduled for later release, and a patch is available in version 4.2.0 and later.
Affected products
- Ni WooCommerce Sales Report before 4.2.0
Timeline
- 2026-09-14: disclosed
- 2026-09-14: patched: Fixed in version 4.2.0