Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.5

CVE-2026-18357: WooCommerce Order Data Exposed via WPC Order Tip Plugin

CVE-2026-18357 · published 26 days ago
Summary

An older version of the WPC Order Tip for WooCommerce plugin on a WordPress site allows hackers to access customer order information without a password. This could let attackers see sensitive details like names and order amounts. To fix this, update the plugin to the latest version (at least 3.3.1) as soon as possible.

What to do
  • Update unknown wpc order tip for woocommerce to version 3.3.1 or later.
Affected software
VendorProductAffected versions
unknown wpc order tip for woocommerce < 3.3.1
Original advisory text
WPC Order Tip for WooCommerce < 3.3.1 - Unauthenticated Order Data Disclosure
The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does not perform authorisation or nonce checks in one of its reporting features, allowing unauthenticated attackers to retrieve sensitive order data belonging to any customer of the store, such as billing names, order IDs and statuses, fee amounts and order dates.
References
Severity
7.5 High
Exploitation
EPSS <1%
Type
CWE-200Information Exposure
Timeline
Published9 Aug 2026
Updated29 Aug 2026
First seen9 Aug 2026
Sources
CVE-2026-18357 · MITRE
Monitor software like this
Free during beta