Weak Order Identifier Generation in Isotope eCommerce by Isotope
CVE-2026-96599
8.2HIGH
What is CVE-2026-96599?
Isotope eCommerce versions up to 2.9.10 utilize a weak method for generating order identifiers, relying on the uniqid() function rather than a cryptographically secure alternative. This vulnerability permits unauthorized attackers to deduce order identifiers. In addition, the lack of proper ownership verification for guest orders enables these attackers to retrieve sensitive information related to orders, such as billing addresses, customer details, and purchased files, by manipulating the uid parameter. This poses significant risks for users, as their private information could easily be compromised.
Affected Version(s)
isotope-core 0 <= 2.9.10
