logo

Clothing Retailer Patches Website Flaw Exposing Customer Data

ID: 0e1fe48c-8299-5d60-a064-c58a25bdbc78

STIX ID: report--0e1fe48c-8299-5d60-a064-c58a25bdbc78

Feed Name: TechRepublic Security

Threat Score
55/100

Date Published: 2026-04-17

Date Updated: 2026-04-23

Author: Joseph Ofonagoro

...
...

A security researcher discovered that Express’ order confirmation pages used sequential order IDs in URLs that could be tweaked to view other customers’ checkout data — including names, emails, phone numbers, postal addresses, order details and the last four digits of payment cards. Express confirmed and patched the issue after the researcher reported it via TechCrunch, but had not publicly notified affected users or fully answered disclosure questions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.