plugin

Live Sales Notifications For Woocommerce Vulnerabilities

4 known security issues reported for the Live Sales Notifications For Woocommerce WordPress plugin. Most recent disclosed Feb 19, 2026.

1 high 1 medium

Running Live Sales Notifications For Woocommerce on your site? Check whether your installed version is affected.

Scan your site free

Live sales notification for WooCommerce [live-sales-notifications-for-woocommerce] <= 2.3.46 (unfixed)

unknown

[en] Missing Authorization vulnerability in PI Web Solution Live sales notification for WooCommerce live-sales-notifications-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Live sales notification for WooCommerce: from n/a through <= 2.3.46.

Affected:
up to 2.3.46
Fix:
No patched version reported
Disclosed:
Feb 19, 2026

CVE-2026-27066 on NVD →

Live sales notification for WooCommerce <= 2.3.46 - Missing Authorization

medium

The Live sales notification for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 2.3.46. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 2.3.46
Fix:
No patched version reported
Disclosed:
Jan 11, 2026

CVE-2026-27066 on NVD →

Live sales notification for WooCommerce [live-sales-notifications-for-woocommerce] < 2.3.40

unknown

[en] The Live sales notification for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.3.39. This is due to the "getOrders" function lacking proper authorization and capability checks when the plugin is configured to display recent order information. This ma...

Affected:
up to 2.3.40
Fixed in:
2.3.40
Disclosed:
Nov 18, 2025

CVE-2025-12955 on NVD →

Live sales notification for WooCommerce <= 2.3.39 - Missing Authorization to Unauthenticated Customer Data Exposure

high

The Live sales notification for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.3.39. This is due to the "getOrders" function lacking proper authorization and capability checks when the plugin is configured to display recent order information. This makes i...

CVSS:
7.5
Affected:
up to 2.3.39
Fixed in:
2.3.40
Disclosed:
Nov 17, 2025

CVE-2025-12955 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database