


Perceptive Security
SOC/SIEM Consultancy

The Order Notification for WooCommerce WordPress plugin before 3.6.3 overrides WooCommerce's permission checks to grant full access to all unauthenticated requ…
Published:
31 maart 2026 om 22:00:00
Alert date:
1 april 2026 om 15:04:53
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
The Order Notification for WooCommerce WordPress plugin versions before 3.6.3 contains a critical authentication bypass vulnerability. The plugin overrides WooCommerce's built-in permission checks, allowing unauthenticated users to gain complete read and write access to all store resources. This includes sensitive data such as products, coupons, and customer information. The vulnerability essentially removes all access controls for the WooCommerce store, making it completely accessible to unauthorized users. This represents a severe security flaw that could lead to complete compromise of e-commerce sites using the vulnerable plugin version.
Technical details
Mitigation steps:
Affected products:
Order Notification for WooCommerce WordPress plugin
WooCommerce
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2025-15484
https://wpscan.com/vulnerability/ee9f1c0c-86bb-4922-9eb5-8aae78003eff/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
