CVE-2023-35876 HIGH

CVE-2023-35876: WordPress WooCommerce Square Plugin <= 3.8.1 is vulnerable to Insecure Direct Object References (IDOR)

Vendor Woocommerce
Product WooCommerce Square
Weakness CWE-639 · IDOR
Published December 20, 2023
Last update April 28, 2026

CVSS base score

8.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

What the vulnerability does

01Description

Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Square.This issue affects WooCommerce Square: from n/a through 3.8.1.

Explanation of Vulnerability in Simple Terms

02Summary

WooCommerce Square versions up to 3.8.1 contain an authorization flaw that allows authenticated users with low privileges to read sensitive payment and order data, and disrupt service availability. The vulnerability stems from insufficient access controls on administrative functions. Attackers need a valid user account but no special permissions to exploit it.

What an attacker can do

03Attacker Capabilities

Read sensitive payment data and order information; disrupt service availability.

Potential impact on your site

04Site Impact

Customer payment records and order details may be exposed to any logged-in user; site availability may be compromised.

Conditions required to exploit

05Prerequisites

Valid WooCommerce user account with low or standard privileges; network access to the site.

Key dates

06Disclosure timeline

December 20, 2023 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE