CVE-2025-26933 HIGH

CVE-2025-26933: WordPress Place Order Without Payment for WooCommerce plugin <= 2.6.7 - Local File Inclusion vulnerability

Vendor Nitin Prakash
Product WC Place Order Without Payment
Weakness CWE-98 · PHP file inclusion
Published March 10, 2025
Last update April 28, 2026

CVSS base score

7.5/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Nitin Prakash WC Place Order Without Payment wc-place-order-without-payment allows PHP Local File Inclusion.This issue affects WC Place Order Without Payment: from n/a through <= 2.6.7.

Explanation of Vulnerability in Simple Terms

02Summary

WC Place Order Without Payment versions up to 2.6.7 contain a vulnerability that allows an attacker to read sensitive data, modify site content, or disrupt service. The attack requires network access and user interaction (such as clicking a malicious link), but no prior authentication. The vulnerability affects the plugin's core functionality and could compromise customer data or order integrity.

What an attacker can do

03Attacker Capabilities

Read sensitive data, modify orders or site content, or cause the site to become unavailable.

Potential impact on your site

04Site Impact

Customer orders, payment data, or site availability could be compromised without warning or authentication.

Conditions required to exploit

05Prerequisites

Attacker must trick a user into clicking a malicious link or visiting a crafted page. No login required.

Key dates

06Disclosure timeline

March 10, 2025 CVE published
April 28, 2026 Record updated