top of page
perceptive_background_267k.jpg

The Order Notification for WooCommerce WordPress plugin before 3.6.3 overrides WooCommerce's permission checks to grant full access to all unauthenticated requ…

Published:

31 March 2026 at 22:00:00

Alert date:

1 April 2026 at 15:04:53

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications

The Order Notification for WooCommerce WordPress plugin versions before 3.6.3 contains a critical authentication bypass vulnerability. The plugin overrides WooCommerce's built-in permission checks, allowing unauthenticated users to gain complete read and write access to all store resources. This includes sensitive data such as products, coupons, and customer information. The vulnerability essentially removes all access controls for the WooCommerce store, making it completely accessible to unauthorized users. This represents a severe security flaw that could lead to complete compromise of e-commerce sites using the vulnerable plugin version.

Technical details

Mitigation steps:

Affected products:

Order Notification for WooCommerce WordPress plugin
WooCommerce

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page