WooCommerce Anti-Fraud <= 7.2.6 - Missing Authorization
medium
The WooCommerce Anti-Fraud plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 7.2.6. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 7.2.6
- Fixed in:
- 7.2.7
- Disclosed:
- Jun 8, 2026
CVE-2026-49072 on NVD →
WooCommerce Anti-Fraud <= 3.2 - Insecure Direct Object Reference
medium
The WooCommerce Anti-Fraud plugin for WordPress is vulnerable to Insecure Direct Object Reference (IDOR) due to insufficient user validation on the paypal_verification() function in versions up to, and including, 3.2. This makes it possible for unauthenticated attackers to change any user's order status.
- CVSS:
- 5.4
- Affected:
- up to 3.2
- Fixed in:
- 3.3
- Disclosed:
- Nov 22, 2020
WooCommerce Anti-Fraud [woocommerce-anti-fraud] < 3.3
unknown
Unauthenticated order status manipulation issue found by Brian Henry in WordPress WooCommerce Anti-Fraud premium plugin (versions <= 3.2).
- Affected:
- up to 3.3
- Fixed in:
- 3.3
- Disclosed:
- Nov 22, 2020
WooCommerce Anti-Fraud [woocommerce-anti-fraud] < 3.3
unknown
The WooCommerce Anti-Fraud plugin for WordPress is vulnerable to Insecure Direct Object Reference (IDOR) due to insufficient user validation on the paypal_verification() function in versions up to, and including, 3.2. This makes it possible for unauthenticated attackers to change any user's order status.
- Affected:
- up to 3.3
- Fixed in:
- 3.3
- Disclosed:
- Nov 22, 2020
WooCommerce Anti-Fraud [woocommerce-anti-fraud] < 3.9
unknown
The plugin is affected by an issue where an unauthenticated user could change the order status of any order to processing, as there were no checks when changing the order status. The order_id was also predictable.
On an individual level, if you have already received your order, you can set the order status back to P...
- Affected:
- up to 3.9
- Fixed in:
- 3.9
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database