Security fixes are provided for the latest released version of NOW Campaign Storefronts for WooCommerce.
Please do not disclose suspected vulnerabilities in a public issue, discussion, support thread, or social post.
Use GitHub private vulnerability reporting for the public NOW Campaign Storefronts repository when available. Include:
- A clear description of the issue.
- Reproduction steps or proof of concept.
- WordPress, WooCommerce, PHP, and NOW Campaign Storefronts versions.
- Whether authentication or a specific capability is required.
- The expected security impact.
Do not include real customer, order, payment, address, or credential data in a report. Use synthetic test data whenever possible.
We will review valid reports and coordinate a fix and disclosure timeline when appropriate.