What is CVE-2026-18357?
The WPC Order Tip for WooCommerce WordPress plugin before version 3.3.1 lacks authorization and nonce checks in a reporting feature, allowing unauthenticated attackers to retrieve sensitive order data of any customer. Immediate update to the latest version is strongly recommended.
Azərbaycanca: WooCommerce üçün WPC Order Tip WordPress plugin-in 3.3.1-dən əvvəlki versiyalarında avtorizasiya və nonce yoxlamasının olmaması autentifikasiya olunmamış hücumçulara hər hansı bir müştərinin həssas sifariş məlumatlarını (ad, sifariş ID-ləri, statuslar) əldə etməyə imkan verir. Plugin-i dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ1
What flaw in the WPC Order Tip for WooCommerce plugin allows unauthenticated attackers to access customer order data?
The lack of authorization and nonce checks in versions prior to 3.3.1.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.