Description
Cross-Site Request Forgery (CSRF) vulnerability in BeRocket Sequential Order Numbers for WooCommerce sequential-order-numbers-for-woocommerce allows Cross Site Request Forgery.This issue affects Sequential Order Numbers for WooCommerce: from n/a through <= 3.6.2.
Published: 2025-04-04
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a classic CSRF flaw that permits an attacker to trigger legitimate actions performed by a logged‑in user within the WordPress site. By crafting a request that exploits the plugin’s lack of proper CSRF protection, an attacker can cause the plugin to execute operations that the user has permission for, potentially altering order numbers or other sensitive data. This weakness is identified as CWE‑352 and does not grant remote code execution, but it can be used to elevate an attacker’s permissions within the scope of the authenticated user.

Affected Systems

The flaw affects the BeRocket Sequential Order Numbers for WooCommerce plugin in all releases up to and including version 3.6.2 on WordPress sites that use WooCommerce. No specific WordPress version constraints are listed, so any site running this plugin within the affected version range is vulnerable.

Risk and Exploitability

The CVSS score of 4.3 reflects a moderate severity, and the EPSS score of less than 1% indicates a low but non‑zero probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, suggesting it has not yet been widely exploited. Attackers would most likely attempt to lure a site administrator or an authenticated user into visiting a crafted URL or clicking a malicious link, thereby using the user’s own credentials to perform unwanted actions.

Generated by OpenCVE AI on May 1, 2026 at 00:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the BeRocket Sequential Order Numbers for WooCommerce plugin to the latest version beyond 3.6.2, if an update is available.
  • If an upgrade is not an option, disable the plugin or remove it entirely from the site to stop the vulnerable functionality.
  • Ensure that the WordPress core and WooCommerce themselves are updated to the latest patched releases to maintain overall site security.
  • Apply a site‑wide CSRF protection mechanism such as a security plugin that enforces CSRF tokens for all POST actions, or configure the existing security settings to require confirmation for privileged operations.

Generated by OpenCVE AI on May 1, 2026 at 00:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-9789 Cross-Site Request Forgery (CSRF) vulnerability in BeRocket Sequential Order Numbers for WooCommerce allows Cross Site Request Forgery. This issue affects Sequential Order Numbers for WooCommerce: from n/a through 3.6.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in BeRocket Sequential Order Numbers for WooCommerce allows Cross Site Request Forgery. This issue affects Sequential Order Numbers for WooCommerce: from n/a through 3.6.2. Cross-Site Request Forgery (CSRF) vulnerability in BeRocket Sequential Order Numbers for WooCommerce sequential-order-numbers-for-woocommerce allows Cross Site Request Forgery.This issue affects Sequential Order Numbers for WooCommerce: from n/a through <= 3.6.2.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Tue, 08 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in BeRocket Sequential Order Numbers for WooCommerce allows Cross Site Request Forgery. This issue affects Sequential Order Numbers for WooCommerce: from n/a through 3.6.2.
Title WordPress Sequential Order Numbers for WooCommerce plugin <= 3.6.2 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:20.078Z

Reserved: 2025-04-04T10:02:22.506Z

Link: CVE-2025-32263

cve-icon Vulnrichment

Updated: 2025-04-08T18:47:29.956Z

cve-icon NVD

Status : Deferred

Published: 2025-04-04T16:15:37.060

Modified: 2026-04-23T15:28:51.747

Link: CVE-2025-32263

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T00:30:04Z

Weaknesses