Order Listener for WooCommerce - Unauthenticated WooCommerce REST Permission Bypass vulnerability
highUnauthenticated WooCommerce REST Permission Bypass vulnerability
- CVSS:
- 7.5
- Affected:
- up to 3.6.3
- Fixed in:
- 3.6.3
- Disclosed:
- Apr 2, 2026
plugin
6 known security issues reported for the Woc Order Alert WordPress plugin. Most recent disclosed Apr 2, 2026.
Running Woc Order Alert on your site? Check whether your installed version is affected.
Scan your site freeUnauthenticated WooCommerce REST Permission Bypass vulnerability
The Order Notification for WooCommerce – Get Audio Alert on new Orders plugin for WordPress is vulnerable to Remote Code Execution in all versions up to 3.6.3 (exclusive). This makes it possible for unauthenticated attackers to execute code on the server.
[en] Missing Authorization vulnerability in ilmosys Order Listener for WooCommerce woc-order-alert allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Listener for WooCommerce: from n/a through <= 3.6.1.
The Order Listener for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.6.1. This makes it possible for unauthenticated attackers to perform an unauthorized action.
[en] The Order Listener for WooCommerce WordPress plugin before 3.2.2 does not sanitise and escape the id parameter before using it in a SQL statement via a REST route available to unauthenticated users, leading to an SQL injection
The Order Listener for WooCommerce WordPress plugin before 3.2.2 does not sanitise and escape the id parameter before using it in a SQL statement via a REST route available to unauthenticated users, leading to an SQL injection
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free