WooCommerce Payments <= 11.1.0 - Unauthenticated Insecure Direct Object Reference to Order Update via 'order_id' Parameter
- ID
- WPSEC-2026-0766
- Plugin
- WooPayments: Integrated WooCommerce Payments (woocommerce-payments)
- Affected
- all versions before 11.2.0
- Remediation
- Update to 11.2.0 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Weakness
- CWE-639
- Usage
- Plugin High · Affected versions High among sites WPSec scans, 2026-10-11
- Attack surface
- WooCommerce Payments on WPSec AttackSurface
- Fix released
- Published
Description
The WooPayments: Integrated WooCommerce Payments plugin for WordPress is vulnerable to Insecure Direct Object Reference via the update_order_status AJAX action in all versions up to, and including, 11.1.0, due to the action's nonce not being bound to a specific order and the user-supplied 'order_id' not being checked against the order the nonce was issued for. This makes it possible for unauthenticated attackers who obtain the nonce while paying for their own order to run the payment-authentication update against other customers' orders by changing the 'order_id' value. They can add order notes to any order and, if they know the order's payment intent ID, re-sync the order's payment status.
References
- https://wpsec.com/vuln/WPSEC-2026-0766/
- https://plugins.svn.wordpress.org/woocommerce-payments/tags/11.2.0/
- https://wordpress.org/plugins/woocommerce-payments/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS