REST API

Authentication Bypass in Customer Reviews for WooCommerce

CVE-2026-4664: a flaw in Customer Reviews for WooCommerce lets unauthenticated attackers post fake Verified reviews via the plugin's REST API.

28 June 2026

Read more

Customer Reviews for WooCommerce: Verified Review Bypass

The Customer Reviews for WooCommerce plugin 5.103.0 and below has a critical weakness that allows attackers to post fake/spam reviews.

22 April 2026

Read more

Unauthenticated RCE in File Uploader for WooCommerce

File Uploader for WooCommerce up to 1.0.3 exposes an unauthenticated REST endpoint that pulls an attacker-controlled file from Uploadcare into the uploads directory with any extension. Full pre-auth RCE (CVE-2025-13329, CVSS 9.8).

9 April 2026

Read more

Unauthenticated REST API Bypass in WooCommerce Order Alert Plugin

Order Notification for WooCommerce (woc-order-alert) plays audio alerts in the browser when new orders come in. It's useful if you're running a busy shop and want a heads-up without refreshing your site's admin dashboard. Before version 3.6.3 there was a serious problem. A permission bypass meant the entire WooCommerce REST API was open to unauthenticated requests. No API keys, no cookies, no login required. It was an absolute howler.

4 April 2026

Read more

Mail Mint: User Email Harvesting via Unauthenticated REST Endpoint

Mail Mint has an unauthenticated REST API endpoint that lets anyone enumerate the email addresses of every registered user on the site.

30 March 2026

Read more