CVE-2025-14886: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-14886 is a missing authorization vulnerability in the Japanized for WooCommerce WordPress plugin that allows unauthenticated attackers to mark any WooCommerce order as processed or completed. It affects all versions of the plugin up to and including 2.7.17. The vulnerability was published on January 9, 2026, and assigned by Wordfence. It carries a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, EUVD).

Technical details

The root cause is a missing capability check (CWE-862) on the order REST API endpoint within the plugin's Paidy payment gateway class (class-wc-paidy-endpoint.php, line 51). Because no authentication or authorization is enforced before processing the request, any unauthenticated network attacker can send a crafted REST API call to update the status of an arbitrary WooCommerce order. No special privileges, user interaction, or complex conditions are required for exploitation (Wordfence, WordPress Trac).

Impact

Successful exploitation allows an unauthenticated attacker to fraudulently mark any WooCommerce order as completed or processed without making a legitimate payment, enabling payment fraud and fulfillment bypass. This primarily affects integrity — merchants could be forced to fulfill orders that were never actually paid, resulting in financial loss. There is no direct confidentiality or availability impact, and the scope is limited to the affected WordPress/WooCommerce installation (Wordfence, EUVD).

Exploitability

No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported as of the time of publication. The EPSS score is approximately 0.051%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified (Wordfence).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Japanized for WooCommerce plugin (versions ≤ 2.7.17) using passive techniques such as checking plugin metadata via /wp-content/plugins/woocommerce-for-japan/readme.txt or using tools like WPScan.
  2. Enumerate order IDs: Discover valid WooCommerce order IDs through publicly accessible order confirmation pages, email enumeration, or sequential guessing (WooCommerce order IDs are typically sequential integers).
  3. Craft REST API request: Send an unauthenticated HTTP request to the vulnerable order REST API endpoint exposed by the plugin's Paidy gateway (e.g., POST /wp-json/<plugin-endpoint>/order with the target order ID and desired status).
  4. Mark order as completed: The endpoint processes the request without verifying the caller's identity or permissions, updating the target order's status to "completed" or "processed" in the WooCommerce database.
  5. Trigger fulfillment: The merchant's system, seeing the order as completed, may automatically dispatch goods or services, resulting in fraudulent fulfillment without payment (Wordfence, WordPress Trac).

Indicators of compromise

  • Network: Unexpected unauthenticated POST requests to the plugin's Paidy REST API endpoint (e.g., /wp-json/*/order) from unknown or suspicious IP addresses, particularly with order ID parameters.
  • Logs: WordPress/WooCommerce access logs showing REST API calls to the Paidy order endpoint without associated authentication tokens or nonces; repeated requests targeting multiple order IDs in rapid succession.
  • Application: WooCommerce orders transitioning to "completed" or "processing" status without corresponding payment gateway confirmation events or payment records in the WooCommerce order notes.

Mitigation and workarounds

Site administrators should update the Japanized for WooCommerce plugin to a version beyond 2.7.17 that includes a proper capability check on the order REST API endpoint. If an immediate update is not possible, consider temporarily disabling the Paidy payment gateway within the plugin settings to remove the vulnerable endpoint from exposure. Additionally, review recent WooCommerce order status changes for anomalies that may indicate prior exploitation (Wordfence).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management