What is CVE-2026-18603?
This vulnerability exists in the "PiWeb Cancel order / Refund request for WooCommerce" WordPress plugin before version 1.3.4.34. It lacks authorization or ownership checks, allowing unauthenticated users to disclose the contents of other customers' orders and clear the cart. Immediate update to the latest version is recommended.
Azərbaycanca: Bu boşluq "PiWeb Cancel order / Refund request for WooCommerce" WordPress plugin-nin 1.3.4.34-dən əvvəlki versiyalarında mövcuddur. O, autentifikasiya və sahiblik yoxlaması olmadığı üçün icazəsiz istifadəçilərə digər müştərilərin sifariş məzmununu ifşa etməyə və səbəti təmizləməyə imkan verir. Plugin-i dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What functionality of the "PiWeb Cancel order / Refund request for WooCommerce" plugin is affected by CVE-2026-18603?
Due to missing authorization and ownership checks, the vulnerability allows unauthenticated users to disclose the contents of other customers' orders and clear their cart.
What measure should be taken to protect against CVE-2026-18603?
It is recommended to immediately update the plugin to version 1.3.4.34 or higher.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.