Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 03 Apr 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Order Notification For Woocommerce
Order Notification For Woocommerce order Notification For Woocommerce Wordpress Wordpress wordpress |
|
| Vendors & Products |
Order Notification For Woocommerce
Order Notification For Woocommerce order Notification For Woocommerce Wordpress Wordpress wordpress |
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-287 | |
| Metrics |
cvssV3_1
|
Wed, 01 Apr 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Order Notification for WooCommerce WordPress plugin before 3.6.3 overrides WooCommerce's permission checks to grant full access to all unauthenticated requests, enabling complete read/write access to store resources like products, coupons, and customers. | |
| Title | Order Notification for WooCommerce < 3.6.3 - Unauthenticated WooCommerce REST Permission Bypass | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-04-01T14:03:41.137Z
Reserved: 2026-01-07T22:08:07.507Z
Link: CVE-2025-15484
Updated: 2026-04-01T14:03:25.608Z
Status : Deferred
Published: 2026-04-01T06:16:14.133
Modified: 2026-04-15T15:05:47.827
Link: CVE-2025-15484
No data.
OpenCVE Enrichment
Updated: 2026-04-03T08:58:47Z