CVE-2026-18357
Received Received - Intake

Unauthenticated Order Data Exposure in WPC Order Tip for WooCommerce

Vulnerability report for CVE-2026-18357, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-09

Last updated on: 2026-08-09

Assigner: WPScan

Description

The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does not perform authorisation or nonce checks in one of its reporting features, allowing unauthenticated attackers to retrieve sensitive order data belonging to any customer of the store, such as billing names, order IDs and statuses, fee amounts and order dates.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-09
Last Modified
2026-08-09
Generated
2026-08-09
AI Q&A
2026-08-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wpc order_tip_for_woocommerce to 3.3.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the WPC Order Tip for WooCommerce WordPress plugin before version 3.3.1. It allows unauthenticated attackers to retrieve sensitive order data from any customer, including billing names, order IDs, statuses, fee amounts, and order dates. The issue occurs due to missing authorization and nonce checks in a reporting feature.

Detection Guidance

To detect this vulnerability, check if the WPC Order Tip for WooCommerce plugin version is below 3.3.1. You can inspect the plugin files for missing authorization or nonce checks in reporting features. Review server logs for unusual requests to order data endpoints.

Impact Analysis

Unauthenticated attackers can access sensitive customer data, leading to privacy breaches, potential identity theft, or misuse of order information. Stores using vulnerable versions risk exposing customer details to unauthorized parties.

Compliance Impact

This vulnerability likely violates GDPR and other privacy regulations by exposing personal data without authorization. It could result in legal penalties, fines, and reputational damage for non-compliance with data protection requirements.

Mitigation Strategies

Immediately update the WPC Order Tip for WooCommerce plugin to version 3.3.1 or later. If updating is not possible, disable the plugin temporarily until an update is applied. Monitor network traffic for unauthorized access attempts to order data endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18357. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart