What is CVE-2026-18945?
The WP Helper Premium WordPress plugin before version 4.7.6 does not verify the 'order key' on its custom order confirmation page and related AJAX actions. This allows unauthenticated attackers to view other customers' order details, including personal information, and modify order data. Updating the plugin to version 4.7.6 or later is strongly recommended.
Azərbaycanca: WP Helper Premium WordPress plugin 4.7.6-dən əvvəlki versiyalarda sifariş təsdiqi səhifəsi və AJAX əməliyyatlarında 'order key' yoxlaması aparmır. Bu, autentifikasiya olunmamış istifadəçilərə digər müştərilərin şəxsi məlumatlarını ehtiva edən sifariş detallarını görməyə və dəyişdirməyə imkan verir. Plugin-i dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Which versions of the WP Helper Premium plugin are affected by CVE-2026-18945?
All versions before 4.7.6 are affected.
What can an unauthenticated attacker do by exploiting CVE-2026-18945?
View other customers' order details, including personal information, and modify order data.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.