Junglewise Threat Intelligence

CVE-2026-78474: Ni WooCommerce Sales Report auth bypass in report-printing

CVE-2026-78474 · Severity: medium · CVSS 5.3 · Published 2026-09-16

Vendors: NI.

Executive brief

The Ni WooCommerce Sales Report plugin for WordPress has an authentication bypass flaw that allows unauthenticated attackers to access sensitive customer and order data. An attacker can retrieve detailed order information, customer contact details, search orders by name or email, and target specific orders without any login credentials. This exposes confidential business and customer data to unauthorized disclosure.

Technical details

The plugin lacks authentication and authorization checks in its report-printing routine, specifically the 'btn_print' parameter handling. This is a sensitive data disclosure vulnerability (CWE-200) affecting versions before 4.2.0. The vulnerability is network-accessible and requires no authentication, user interaction, or special privileges; an unauthenticated attacker can craft requests to the vulnerable endpoint to retrieve WooCommerce order details and customer contact information. The vulnerability was publicly disclosed on 2026-09-14 with a proof-of-concept scheduled for later release, and a patch is available in version 4.2.0 and later.

Affected products

  • Ni WooCommerce Sales Report before 4.2.0

Timeline

  • 2026-09-14: disclosed
  • 2026-09-14: patched: Fixed in version 4.2.0

References

Related threats