{
 "id": "WPSEC-2026-0766",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0766/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0766/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0766/index.md",
 "title": "WooCommerce Payments <= 11.1.0 - Unauthenticated Insecure Direct Object Reference to Order Update via 'order_id' Parameter",
 "description": "The WooPayments: Integrated WooCommerce Payments plugin for WordPress is vulnerable to Insecure Direct Object Reference via the update_order_status AJAX action in all versions up to, and including, 11.1.0, due to the action's nonce not being bound to a specific order and the user-supplied 'order_id' not being checked against the order the nonce was issued for. This makes it possible for unauthenticated attackers who obtain the nonce while paying for their own order to run the payment-authentication update against other customers' orders by changing the 'order_id' value. They can add order notes to any order and, if they know the order's payment intent ID, re-sync the order's payment status.",
 "plugin": {
  "slug": "woocommerce-payments",
  "name": "WooCommerce Payments",
  "full_name": "WooPayments: Integrated WooCommerce Payments",
  "wordpress_org": "https://wordpress.org/plugins/woocommerce-payments/",
  "advisories_url": "https://wpsec.com/vuln/plugin/woocommerce-payments/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/woocommerce-payments"
 },
 "type": "IDOR",
 "cwe": [
  "CWE-639"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.3,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "11.2.0",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 11.2.0"
  ]
 },
 "introduced_in": null,
 "fixed_in": "11.2.0",
 "remediation": "Update to 11.2.0 or later.",
 "fix_released": "2026-10-08T13:50:10+00:00",
 "published": "2026-10-11T12:43:38+00:00",
 "updated": "2026-10-11T11:37:56.567581+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0766/",
  "https://plugins.svn.wordpress.org/woocommerce-payments/tags/11.2.0/",
  "https://wordpress.org/plugins/woocommerce-payments/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/woocommerce-payments",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "High",
  "affected_versions": "High",
  "as_of": "2026-10-11"
 }
}