
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27374 is a Missing Authorization vulnerability in the WooCommerce Order Details WordPress plugin (by vanquish) that allows unauthenticated attackers to exploit incorrectly configured access control security levels. The vulnerability affects all versions of the plugin through 3.1 (inclusive). It was published on March 5, 2026, and assigned by Patchstack. It carries a CVSS v3.1 base score of 7.5 (High) (Feedly, Patchstack).
The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether a requesting user has the necessary permissions before granting access to sensitive functionality or data. The attack vector is network-based, requires no authentication, no user interaction, and low attack complexity, making it trivially exploitable by any remote attacker. The flaw falls under the broader category of broken access control, where order detail data — typically restricted to authenticated customers or administrators — may be accessible without proper authorization checks (Feedly, Patchstack).
Successful exploitation results in a high confidentiality impact with no integrity or availability impact, meaning attackers can read sensitive WooCommerce order information — such as customer names, addresses, email addresses, order contents, and payment details — without authentication. This data exposure could facilitate follow-on attacks including phishing, identity theft, or fraud targeting affected customers. The scope is limited to the affected WordPress/WooCommerce installation, but the breadth of customer data stored in order records makes the potential harm significant (Feedly).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.017% (0.000170), indicating a low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified (Feedly).
/wp-content/plugins/woocommerce-order-details/).wp-admin/admin-ajax.php action registered by the plugin).admin-ajax.php with order-related action parameters from unknown or external IP addresses.The primary remediation is to update the WooCommerce Order Details plugin to a version beyond 3.1 that includes the authorization fix, once a patched release is made available by the vendor (vanquish). Until a patch is available, site administrators should consider deactivating or removing the plugin to eliminate the attack surface. Additionally, implementing a Web Application Firewall (WAF) rule to block unauthenticated access to order detail endpoints can serve as a temporary mitigation (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."