Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.3

Alma Gateway for WooCommerce: Incorrect Access Control Exposes Customer Data

CVE-2026-24999
Summary

A security issue in Alma Gateway for WooCommerce allows unauthorized users to access customer data if access control settings are not properly configured. This can lead to sensitive information being exposed. Update Alma Gateway for WooCommerce to the latest version to address this issue.

Original title
Missing Authorization vulnerability in Alma Alma alma-gateway-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Alma: from n/a through <= 5....
Original description
Missing Authorization vulnerability in Alma Alma alma-gateway-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Alma: from n/a through <= 5.16.1.
nvd CVSS3.1 5.3
Vulnerability type
CWE-862 Missing Authorization
Published: 19 Feb 2026 · Updated: 11 Mar 2026 · First seen: 6 Mar 2026