CVE-2026-27374: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-27374 is a Missing Authorization vulnerability in the WooCommerce Order Details WordPress plugin (by vanquish) that allows unauthenticated attackers to exploit incorrectly configured access control security levels. The vulnerability affects all versions of the plugin through 3.1 (inclusive). It was published on March 5, 2026, and assigned by Patchstack. It carries a CVSS v3.1 base score of 7.5 (High) (Feedly, Patchstack).

Technical details

The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether a requesting user has the necessary permissions before granting access to sensitive functionality or data. The attack vector is network-based, requires no authentication, no user interaction, and low attack complexity, making it trivially exploitable by any remote attacker. The flaw falls under the broader category of broken access control, where order detail data — typically restricted to authenticated customers or administrators — may be accessible without proper authorization checks (Feedly, Patchstack).

Impact

Successful exploitation results in a high confidentiality impact with no integrity or availability impact, meaning attackers can read sensitive WooCommerce order information — such as customer names, addresses, email addresses, order contents, and payment details — without authentication. This data exposure could facilitate follow-on attacks including phishing, identity theft, or fraud targeting affected customers. The scope is limited to the affected WordPress/WooCommerce installation, but the breadth of customer data stored in order records makes the potential harm significant (Feedly).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.017% (0.000170), indicating a low probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been identified (Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the WooCommerce Order Details plugin (version ≤ 3.1) using tools like WPScan, Shodan, or by inspecting plugin directories (/wp-content/plugins/woocommerce-order-details/).
  2. Identify vulnerable endpoint: Locate the plugin's order detail retrieval endpoint or AJAX action that lacks proper authorization checks (e.g., a REST API route or wp-admin/admin-ajax.php action registered by the plugin).
  3. Craft unauthenticated request: Send an HTTP GET or POST request to the identified endpoint without authentication credentials, supplying a target order ID (which may be guessable or enumerable sequentially).
  4. Extract order data: Parse the response to retrieve sensitive customer and order information such as billing address, email, purchased items, and order totals.
  5. Enumerate further: Repeat with incremented order IDs to harvest data across multiple customer orders (Feedly).

Indicators of compromise

  • Network: Unusual unauthenticated HTTP requests to WooCommerce order detail endpoints or admin-ajax.php with order-related action parameters from unknown or external IP addresses.
  • Logs: WordPress/web server access logs showing repeated requests to plugin-specific endpoints with sequential or varied order ID parameters, originating from a single IP or user agent without a valid session cookie.
  • Logs: High volume of 200 OK responses to order detail requests from unauthenticated sessions in a short time window.

Mitigation and workarounds

The primary remediation is to update the WooCommerce Order Details plugin to a version beyond 3.1 that includes the authorization fix, once a patched release is made available by the vendor (vanquish). Until a patch is available, site administrators should consider deactivating or removing the plugin to eliminate the attack surface. Additionally, implementing a Web Application Firewall (WAF) rule to block unauthenticated access to order detail endpoints can serve as a temporary mitigation (Patchstack).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management