PT-2026-71393 · WordPress · Wp Helper Premium
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
WP Helper Premium versions prior to 4.7.6
Description
Insufficient verification of the order key occurs when rendering the custom order confirmation page or handling related AJAX actions. This allows unauthenticated users to view personal information and order details of other customers, as well as modify the state of arbitrary orders. This issue requires WooCommerce to be active and the optional order confirmation page module of the plugin to be enabled.
Recommendations
Update WP Helper Premium to version 4.7.6 or later.
As a temporary mitigation, disable the optional order confirmation page module.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Helper Premium