
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14886 is a missing authorization vulnerability in the Japanized for WooCommerce WordPress plugin that allows unauthenticated attackers to mark any WooCommerce order as processed or completed. It affects all versions of the plugin up to and including 2.7.17. The vulnerability was published on January 9, 2026, and assigned by Wordfence. It carries a CVSS v3.1 base score of 5.3 (Medium) (Wordfence, EUVD).
The root cause is a missing capability check (CWE-862) on the order REST API endpoint within the plugin's Paidy payment gateway class (class-wc-paidy-endpoint.php, line 51). Because no authentication or authorization is enforced before processing the request, any unauthenticated network attacker can send a crafted REST API call to update the status of an arbitrary WooCommerce order. No special privileges, user interaction, or complex conditions are required for exploitation (Wordfence, WordPress Trac).
Successful exploitation allows an unauthenticated attacker to fraudulently mark any WooCommerce order as completed or processed without making a legitimate payment, enabling payment fraud and fulfillment bypass. This primarily affects integrity — merchants could be forced to fulfill orders that were never actually paid, resulting in financial loss. There is no direct confidentiality or availability impact, and the scope is limited to the affected WordPress/WooCommerce installation (Wordfence, EUVD).
No public proof-of-concept exploit code or evidence of active in-the-wild exploitation has been reported as of the time of publication. The EPSS score is approximately 0.051%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified (Wordfence).
/wp-content/plugins/woocommerce-for-japan/readme.txt or using tools like WPScan.order REST API endpoint exposed by the plugin's Paidy gateway (e.g., POST /wp-json/<plugin-endpoint>/order with the target order ID and desired status)./wp-json/*/order) from unknown or suspicious IP addresses, particularly with order ID parameters.Site administrators should update the Japanized for WooCommerce plugin to a version beyond 2.7.17 that includes a proper capability check on the order REST API endpoint. If an immediate update is not possible, consider temporarily disabling the Paidy payment gateway within the plugin settings to remove the vulnerable endpoint from exposure. Additionally, review recent WooCommerce order status changes for anomalies that may indicate prior exploitation (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."