Authentication Bypass in Customer Reviews for WooCommerce
CVE-2026-4664: a flaw in Customer Reviews for WooCommerce lets unauthenticated attackers post fake Verified reviews via the plugin's REST API.
28 June 2026
Read moreCustomer Reviews for WooCommerce: Verified Review Bypass
The Customer Reviews for WooCommerce plugin 5.103.0 and below has a critical weakness that allows attackers to post fake/spam reviews.
22 April 2026
Read moreUnauthenticated RCE in File Uploader for WooCommerce
File Uploader for WooCommerce up to 1.0.3 exposes an unauthenticated REST endpoint that pulls an attacker-controlled file from Uploadcare into the uploads directory with any extension. Full pre-auth RCE (CVE-2025-13329, CVSS 9.8).
9 April 2026
Read moreUnauthenticated REST API Bypass in WooCommerce Order Alert Plugin
Order Notification for WooCommerce (woc-order-alert) plays audio alerts in the browser when new orders come in. It's useful if you're running a busy shop and want a heads-up without refreshing your site's admin dashboard. Before version 3.6.3 there was a serious problem. A permission bypass meant the entire WooCommerce REST API was open to unauthenticated requests. No API keys, no cookies, no login required. It was an absolute howler.
4 April 2026
Read moreMail Mint: User Email Harvesting via Unauthenticated REST Endpoint
Mail Mint has an unauthenticated REST API endpoint that lets anyone enumerate the email addresses of every registered user on the site.
30 March 2026
Read more