plugin

Woocommerce Anti Fraud Vulnerabilities

5 known security issues reported for the Woocommerce Anti Fraud WordPress plugin. Most recent disclosed Jun 8, 2026.

2 medium

Running Woocommerce Anti Fraud on your site? Check whether your installed version is affected.

Scan your site free

WooCommerce Anti-Fraud <= 7.2.6 - Missing Authorization

medium

The WooCommerce Anti-Fraud plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 7.2.6. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 7.2.6
Fixed in:
7.2.7
Disclosed:
Jun 8, 2026

CVE-2026-49072 on NVD →

WooCommerce Anti-Fraud <= 3.2 - Insecure Direct Object Reference

medium

The WooCommerce Anti-Fraud plugin for WordPress is vulnerable to Insecure Direct Object Reference (IDOR) due to insufficient user validation on the paypal_verification() function in versions up to, and including, 3.2. This makes it possible for unauthenticated attackers to change any user's order status.

CVSS:
5.4
Affected:
up to 3.2
Fixed in:
3.3
Disclosed:
Nov 22, 2020

WooCommerce Anti-Fraud [woocommerce-anti-fraud] < 3.3

unknown

Unauthenticated order status manipulation issue found by Brian Henry in WordPress WooCommerce Anti-Fraud premium plugin (versions <= 3.2).

Affected:
up to 3.3
Fixed in:
3.3
Disclosed:
Nov 22, 2020

WooCommerce Anti-Fraud [woocommerce-anti-fraud] < 3.3

unknown

The WooCommerce Anti-Fraud plugin for WordPress is vulnerable to Insecure Direct Object Reference (IDOR) due to insufficient user validation on the paypal_verification() function in versions up to, and including, 3.2. This makes it possible for unauthenticated attackers to change any user's order status.

Affected:
up to 3.3
Fixed in:
3.3
Disclosed:
Nov 22, 2020

WooCommerce Anti-Fraud [woocommerce-anti-fraud] < 3.9

unknown

The plugin is affected by an issue where an unauthenticated user could change the order status of any order to processing, as there were no checks when changing the order status. The order_id was also predictable. On an individual level, if you have already received your order, you can set the order status back to P...

Affected:
up to 3.9
Fixed in:
3.9

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database