What the vulnerability does
01Description
The Order Notification for WooCommerce WordPress plugin before 3.6.3 overrides WooCommerce's permission checks to grant full access to all unauthenticated requests, enabling complete read/write access to store resources like products, coupons, and customers.
Explanation of Vulnerability in Simple Terms
02Summary
A vulnerability exists in Order Notification for WooCommerce versions before 3.6.3. The specific attack vector and impact are not yet documented in available sources. Site administrators should update to version 3.6.3 or later to ensure protection. Check the plugin's changelog for details on what was fixed.
What an attacker can do
03Attacker Capabilities
Unknown; insufficient technical details available.
Potential impact on your site
04Site Impact
Update Order Notification for WooCommerce to version 3.6.3 or later to patch this vulnerability.
Conditions required to exploit
05Prerequisites
Unknown; insufficient technical details available.
Key dates
06Disclosure timeline
April 1, 2026
CVE published
April 1, 2026
Record updated