plugin

Woc Order Alert Vulnerabilities

6 known security issues reported for the Woc Order Alert WordPress plugin. Most recent disclosed Apr 2, 2026.

1 critical 1 high 2 medium

Running Woc Order Alert on your site? Check whether your installed version is affected.

Scan your site free

Order Listener for WooCommerce - Unauthenticated WooCommerce REST Permission Bypass vulnerability

high

Unauthenticated WooCommerce REST Permission Bypass vulnerability

CVSS:
7.5
Affected:
up to 3.6.3
Fixed in:
3.6.3
Disclosed:
Apr 2, 2026

Order Notification for WooCommerce – Get Audio Alert on new Orders < 3.6.3 - Unauthenticated Remote Code Execution

critical

The Order Notification for WooCommerce – Get Audio Alert on new Orders plugin for WordPress is vulnerable to Remote Code Execution in all versions up to 3.6.3 (exclusive). This makes it possible for unauthenticated attackers to execute code on the server.

CVSS:
9.8
Affected:
up to 3.6.3
Fixed in:
3.6.3
Disclosed:
Apr 2, 2026

CVE-2025-15484 on NVD →

Order Notification for WooCommerce – Get Audio Alert on new Orders [woc-order-alert] <= 3.6.1 (unfixed)

unknown

[en] Missing Authorization vulnerability in ilmosys Order Listener for WooCommerce woc-order-alert allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Order Listener for WooCommerce: from n/a through <= 3.6.1.

Affected:
up to 3.6.1
Fix:
No patched version reported
Disclosed:
Jan 22, 2026

CVE-2025-68018 on NVD →

Order Listener for WooCommerce <= 3.6.1 - Missing Authorization

medium

The Order Listener for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 3.6.1. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 3.6.1
Fixed in:
3.6.2
Disclosed:
Jan 19, 2026

CVE-2025-68018 on NVD →

Order Notification for WooCommerce – Get Audio Alert on new Orders [woc-order-alert] < 3.2.2

unknown

[en] The Order Listener for WooCommerce WordPress plugin before 3.2.2 does not sanitise and escape the id parameter before using it in a SQL statement via a REST route available to unauthenticated users, leading to an SQL injection

Affected:
up to 3.2.2
Fixed in:
3.2.2
Disclosed:
May 9, 2022

CVE-2022-0948 on NVD →

Order Listener for WooCommerce – Play Sounds Instantly on New Orders <= 3.2.1 - Unauthenticated SQL Injection

medium

The Order Listener for WooCommerce WordPress plugin before 3.2.2 does not sanitise and escape the id parameter before using it in a SQL statement via a REST route available to unauthenticated users, leading to an SQL injection

CVSS:
6.5
Affected:
up to 3.2.2
Fixed in:
3.2.2
Disclosed:
Apr 12, 2022

CVE-2022-0948 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database