CVE-2026-18357
7.5WPC · WPC Order Tip for WooCommerce
The WPC Order Tip for WooCommerce plugin before 3.3.1 fails to enforce authorization checks, allowing unauthenticated attackers to access sensitive customer order data.
Executive summary
An unauthenticated information disclosure vulnerability in the WPC Order Tip for WooCommerce plugin permits unauthorized access to sensitive customer order information.
Vulnerability
The plugin fails to perform necessary authorization or nonce checks within its reporting functionality. This oversight allows unauthenticated attackers to retrieve sensitive order data, including billing names, order IDs, and statuses.
Business impact
This vulnerability carries a CVSS score of 7.5, indicating a high severity risk. Successful exploitation could lead to significant data privacy breaches, the exposure of customer personally identifiable information, and potential regulatory non-compliance. These outcomes may result in reputational damage and loss of consumer trust.
Remediation
Immediate Action: Update the WPC Order Tip for WooCommerce plugin to version 3.3.1 or later.
Proactive Monitoring: Review web server and application access logs for unusual patterns of requests targeting reporting endpoints or administrative URL structures.
Compensating Controls: Implement a Web Application Firewall (WAF) rule to block unauthorized access attempts to plugin-specific reporting paths until the update is applied.
Exploitation status
Public Exploit Available: Yes, public proof-of-concept exploits are available.
Analyst recommendation
Given the high CVSS severity and the availability of public proof-of-concept code, this vulnerability poses a clear and present risk to store integrity. Administrators should prioritize updating the plugin immediately to the patched version to prevent unauthorized data exfiltration.