CVE-2026-18357
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-18357 is an unauthenticated order data disclosure vulnerability in the WPC Order Tip for WooCommerce WordPress plugin affecting all versions before 3.3.1. The flaw allows unauthenticated attackers to retrieve sensitive customer order data — including billing names, order IDs and statuses, fee amounts, and order dates — via a reporting feature that lacks authorization and nonce checks. It was publicly disclosed on August 3, 2026, and assigned a CVSS score of 5.3 (Medium) (WPScan, GitHub Advisory).

Technical details

The root cause is a missing authorization and nonce verification check (CWE-200: Information Exposure) in one of the plugin's reporting feature endpoints. Because no authentication or CSRF token validation is enforced, any unauthenticated network attacker can send a direct HTTP request to the vulnerable reporting endpoint and receive sensitive order data in response. The vulnerability was discovered and reported by researcher Farid Narimanov. A proof-of-concept is scheduled for public release on August 17, 2026, to allow time for users to update (WPScan).

Impact

Successful exploitation exposes sensitive WooCommerce customer data — including billing names, order IDs, order statuses, fee amounts, and order dates — to any unauthenticated attacker with network access to the WordPress site. This constitutes a confidentiality breach affecting all customers of the store, and the exposed data could be leveraged for targeted phishing, social engineering, or fraud. Integrity and availability of the system are not directly impacted by this vulnerability (WPScan, GitHub Advisory).

Exploitability

There is currently no public proof-of-concept exploit available, and no evidence of in-the-wild exploitation has been reported. The PoC is scheduled for disclosure on August 17, 2026. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. However, the unauthenticated nature of the attack — requiring no credentials or special privileges — makes it trivially exploitable once technical details are public (WPScan, GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the WPC Order Tip for WooCommerce plugin (versions before 3.3.1) using tools like WPScan, Shodan, or by inspecting plugin directories at /wp-content/plugins/wpc-order-tip/.
  2. Locate the vulnerable endpoint: Identify the unauthenticated reporting feature endpoint exposed by the plugin (specific endpoint details are withheld pending PoC release on August 17, 2026).
  3. Send unauthenticated request: Craft and send an HTTP GET or POST request directly to the reporting endpoint without any authentication token or nonce, as the plugin performs no authorization or nonce validation.
  4. Retrieve order data: Parse the response to extract sensitive customer data including billing names, order IDs, order statuses, fee amounts, and order dates for all store customers (WPScan).

Indicators of compromise

  • Network: Unusual unauthenticated HTTP requests to WooCommerce/WPC Order Tip reporting endpoints from external or unexpected IP addresses; repeated requests to plugin-specific AJAX handlers (e.g., wp-admin/admin-ajax.php with plugin-specific action parameters) without session cookies.
  • Logs: WordPress or web server access logs showing requests to the plugin's reporting endpoint from unauthenticated sessions (no valid WordPress auth cookies); high-frequency requests to the same endpoint from a single IP suggesting automated scraping.
  • File System: No file-based artifacts are expected for this read-only data disclosure vulnerability.

Mitigation and workarounds

Update the WPC Order Tip for WooCommerce plugin to version 3.3.1 or later, which introduces proper authorization and nonce checks on the affected reporting feature. If immediate patching is not possible, consider temporarily disabling the plugin until the update can be applied. After patching, review web server and WordPress access logs to determine whether the vulnerability was exploited and assess potential customer data exposure (WPScan, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18603NONEN/A
  • cancel-order-request-woocommerce
NoYesAug 09, 2026
CVE-2026-18473NONEN/A
  • wpdirectorykit
NoYesAug 09, 2026
CVE-2026-18465NONEN/A
  • wp-google-map-gold
NoYesAug 09, 2026
CVE-2026-18464NONEN/A
  • wp-google-map-gold
NoYesAug 09, 2026
CVE-2026-18357NONEN/A
  • wpc-order-tip
NoYesAug 09, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management