What the vulnerability does
01Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Nitin Prakash WC Place Order Without Payment wc-place-order-without-payment allows PHP Local File Inclusion.This issue affects WC Place Order Without Payment: from n/a through <= 2.6.7.
Explanation of Vulnerability in Simple Terms
02Summary
WC Place Order Without Payment versions up to 2.6.7 contain a vulnerability that allows an attacker to read sensitive data, modify site content, or disrupt service. The attack requires network access and user interaction (such as clicking a malicious link), but no prior authentication. The vulnerability affects the plugin's core functionality and could compromise customer data or order integrity.
What an attacker can do
03Attacker Capabilities
Read sensitive data, modify orders or site content, or cause the site to become unavailable.
Potential impact on your site
04Site Impact
Customer orders, payment data, or site availability could be compromised without warning or authentication.
Conditions required to exploit
05Prerequisites
Attacker must trick a user into clicking a malicious link or visiting a crafted page. No login required.
Key dates
06Disclosure timeline
March 10, 2025
CVE published
April 28, 2026
Record updated