PT-2026-69273 · WordPress · Order Tip For Woocommerce

·

CVE-2026-18357

·

Published

2026-08-09

·

Updated

2026-08-09

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WPC Order Tip for WooCommerce versions prior to 3.3.1
Description A reporting feature fails to perform authorization or nonce checks. A nonce is a unique token used to protect against cross-site request forgery. This flaw allows unauthenticated attackers to retrieve sensitive order data from any customer, including billing names, order IDs, order statuses, fee amounts, and order dates.
Recommendations Update WPC Order Tip for WooCommerce to version 3.3.1 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18357

Affected Products

Order Tip For Woocommerce