The Order Notification for WooCommerce WordPress plugin before 3.6.3 overrides WooCommerce's permission checks to grant full access to all unauthenticated requests, enabling complete read/write access to store resources like products, coupons, and customers.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 01 Apr 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Order Notification for WooCommerce WordPress plugin before 3.6.3 overrides WooCommerce's permission checks to grant full access to all unauthenticated requests, enabling complete read/write access to store resources like products, coupons, and customers. | |
| Title | Order Notification for WooCommerce < 3.6.3 - Unauthenticated WooCommerce REST Permission Bypass | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-04-01T06:00:05.052Z
Reserved: 2026-01-07T22:08:07.507Z
Link: CVE-2025-15484
No data.
Status : Received
Published: 2026-04-01T06:16:14.133
Modified: 2026-04-01T06:16:14.133
Link: CVE-2025-15484
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.