The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does not perform authorisation or nonce checks in one of its reporting features, allowing unauthenticated attackers to retrieve sensitive order data belonging to any customer of the store, such as billing names, order IDs and statuses, fee amounts and order dates.
History

Mon, 10 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 09 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does not perform authorisation or nonce checks in one of its reporting features, allowing unauthenticated attackers to retrieve sensitive order data belonging to any customer of the store, such as billing names, order IDs and statuses, fee amounts and order dates.
Title WPC Order Tip for WooCommerce < 3.3.1 - Unauthenticated Order Data Disclosure
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2026-08-09T06:00:13.226Z

Updated: 2026-08-10T19:38:21.414Z

Reserved: 2026-07-30T08:20:25.072Z

Link: CVE-2026-18357

cve-icon Vulnrichment

Updated: 2026-08-10T19:38:16.259Z

cve-icon NVD

Status : Deferred

Published: 2026-08-09T06:18:34.330

Modified: 2026-08-26T16:31:16.753

Link: CVE-2026-18357

cve-icon Redhat

No data.