Sensitive Data Exposure in Kit for WooCommerce by ConvertKit
CVE-2026-57753

5.3MEDIUM

What is CVE-2026-57753?

An issue has been identified in Kit for WooCommerce, previously known as ConvertKit, allowing unauthenticated users to access sensitive data. This vulnerability affects versions 2.1.5 and earlier, potentially exposing critical information to unauthorized entities. It's essential for website owners utilizing this plugin to assess their security posture and implement necessary updates to safeguard sensitive user data.

Affected Version(s)

Kit (formerly ConvertKit) for WooCommerce <= 2.1.5

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Ba Khanh | Patchstack Bug Bounty Program
.