WooCommerce Payments <= 11.1.0 - Unauthenticated Insecure Direct Object Reference to Order Update via 'order_id' Parameter

Medium 5.3 CWE-639Fixed in 11.2.0
ID
WPSEC-2026-0766
Plugin
WooPayments: Integrated WooCommerce Payments (woocommerce-payments)
Affected
all versions before 11.2.0
Remediation
Update to 11.2.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness
CWE-639
Usage
Plugin High · Affected versions High among sites WPSec scans, 2026-10-11
Attack surface
WooCommerce Payments on WPSec AttackSurface
Fix released
Published

Description

The WooPayments: Integrated WooCommerce Payments plugin for WordPress is vulnerable to Insecure Direct Object Reference via the update_order_status AJAX action in all versions up to, and including, 11.1.0, due to the action's nonce not being bound to a specific order and the user-supplied 'order_id' not being checked against the order the nonce was issued for. This makes it possible for unauthenticated attackers who obtain the nonce while paying for their own order to run the payment-authentication update against other customers' orders by changing the 'order_id' value. They can add order notes to any order and, if they know the order's payment intent ID, re-sync the order's payment status.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0