# WooCommerce Payments <= 11.1.0 - Unauthenticated Insecure Direct Object Reference to Order Update via 'order_id' Parameter

- **ID:** WPSEC-2026-0766
- **Plugin:** WooPayments: Integrated WooCommerce Payments (`woocommerce-payments`), https://wordpress.org/plugins/woocommerce-payments/
- **Affected versions:** all versions before 11.2.0
- **Fixed in:** 11.2.0 (Update to 11.2.0 or later.)
- **Severity:** Medium 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
- **Weakness:** CWE-639
- **Usage among sites WPSec scans:** plugin High, affected versions High (as of 2026-10-11)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/woocommerce-payments
- **Fix released:** 2026-10-08
- **Published:** 2026-10-11
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0766/

## Description

The WooPayments: Integrated WooCommerce Payments plugin for WordPress is vulnerable to Insecure Direct Object Reference via the update_order_status AJAX action in all versions up to, and including, 11.1.0, due to the action's nonce not being bound to a specific order and the user-supplied 'order_id' not being checked against the order the nonce was issued for. This makes it possible for unauthenticated attackers who obtain the nonce while paying for their own order to run the payment-authentication update against other customers' orders by changing the 'order_id' value. They can add order notes to any order and, if they know the order's payment intent ID, re-sync the order's payment status.

## References

- https://wpsec.com/vuln/WPSEC-2026-0766/
- https://plugins.svn.wordpress.org/woocommerce-payments/tags/11.2.0/
- https://wordpress.org/plugins/woocommerce-payments/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0766/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
