plugin

Wpc Order Tip Vulnerabilities

1 known security issue reported for the Wpc Order Tip WordPress plugin. Most recent disclosed Aug 3, 2026.

1 medium

Running Wpc Order Tip on your site? Check whether your installed version is affected.

Scan your site free

WPC Order Tip for WooCommerce <= 3.3.0 - Information Exposure to Unauthenticated Order Data Disclosure

medium

The WPC Order Tip for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.3.0. This is due to missing capability check and nonce verification on the wpcot_display_reports AJAX handler. This makes it possible for unauthenticated attackers to access order t...

CVSS:
5.3
Affected:
up to 3.3.0
Fixed in:
3.3.1
Disclosed:
Aug 3, 2026

CVE-2026-18357 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database