
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-18357 is an unauthenticated order data disclosure vulnerability in the WPC Order Tip for WooCommerce WordPress plugin affecting all versions before 3.3.1. The flaw allows unauthenticated attackers to retrieve sensitive customer order data — including billing names, order IDs and statuses, fee amounts, and order dates — via a reporting feature that lacks authorization and nonce checks. It was publicly disclosed on August 3, 2026, and assigned a CVSS score of 5.3 (Medium) (WPScan, GitHub Advisory).
The root cause is a missing authorization and nonce verification check (CWE-200: Information Exposure) in one of the plugin's reporting feature endpoints. Because no authentication or CSRF token validation is enforced, any unauthenticated network attacker can send a direct HTTP request to the vulnerable reporting endpoint and receive sensitive order data in response. The vulnerability was discovered and reported by researcher Farid Narimanov. A proof-of-concept is scheduled for public release on August 17, 2026, to allow time for users to update (WPScan).
Successful exploitation exposes sensitive WooCommerce customer data — including billing names, order IDs, order statuses, fee amounts, and order dates — to any unauthenticated attacker with network access to the WordPress site. This constitutes a confidentiality breach affecting all customers of the store, and the exposed data could be leveraged for targeted phishing, social engineering, or fraud. Integrity and availability of the system are not directly impacted by this vulnerability (WPScan, GitHub Advisory).
There is currently no public proof-of-concept exploit available, and no evidence of in-the-wild exploitation has been reported. The PoC is scheduled for disclosure on August 17, 2026. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. However, the unauthenticated nature of the attack — requiring no credentials or special privileges — makes it trivially exploitable once technical details are public (WPScan, GitHub Advisory).
/wp-content/plugins/wpc-order-tip/.wp-admin/admin-ajax.php with plugin-specific action parameters) without session cookies.Update the WPC Order Tip for WooCommerce plugin to version 3.3.1 or later, which introduces proper authorization and nonce checks on the affected reporting feature. If immediate patching is not possible, consider temporarily disabling the plugin until the update can be applied. After patching, review web server and WordPress access logs to determine whether the vulnerability was exploited and assess potential customer data exposure (WPScan, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."