Description
The WP Helper Premium WordPress plugin before 4.7.6 does not verify the order key when rendering its custom order confirmation page or when handling the related AJAX actions, allowing unauthenticated users to view other customers' order details, including personal information, as well as change the state of arbitrary orders.

Exploitation requires WooCommerce to be active and the WP Helper Premium WordPress plugin before 4.7.6's optional order confirmation page module to be enabled.
Published: 2026-08-13
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WP Helper Premium WordPress plugin before version 4.7.6 fails to verify an order key when rendering a custom order confirmation page or when processing related Ajax actions, enabling unauthenticated users to access detailed order information and modify the status of arbitrary orders. This flaw results in the disclosure of personal customer data and the potential alteration of order states, compromising both confidentiality and integrity of transactional data.

Affected Systems

The vulnerability affects installations of the WP Helper Premium plugin where the optional order confirmation page module is enabled and WooCommerce is active. The flaw applies to all plugin versions prior to 4.7.6; no specific patch version list is provided. Org admin should check the plugin version and ensure WooCommerce is present.

Risk and Exploitability

Because the flaw is exploitable without authentication and requires only that WooCommerce and the order confirmation module be active, the risk level is high. No CVSS rating is listed, and EPSS is unavailable, but the exposure of customer data and the ability to manipulate orders suggest significant impact. The vulnerability is not currently listed in CISA’s KEV catalog. The likely attack vector is unauthenticated external access to order confirmation URLs or Ajax endpoints; based on the description, it is inferred that remote, web‑based exploitation is possible with no special privileges.

Generated by OpenCVE AI on August 13, 2026 at 07:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update WP Helper Premium to version 4.7.6 or later to gain the order key validation fix
  • If the plugin cannot be updated immediately, temporarily disable the optional order confirmation page module or remove access to related Ajax endpoints until the patch is applied
  • Implement additional access controls or WAF rules to restrict unauthenticated access to order‑related endpoints as a temporary protective measure

Generated by OpenCVE AI on August 13, 2026 at 07:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-285

Thu, 13 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The WP Helper Premium WordPress plugin before 4.7.6 does not verify the order key when rendering its custom order confirmation page or when handling the related AJAX actions, allowing unauthenticated users to view other customers' order details, including personal information, as well as change the state of arbitrary orders. Exploitation requires WooCommerce to be active and the WP Helper Premium WordPress plugin before 4.7.6's optional order confirmation page module to be enabled.
Title WP Helper Premium < 4.7.6 - Unauthenticated Order Data Disclosure and Order Manipulation via Missing Order Key Validation
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-13T06:00:13.806Z

Reserved: 2026-08-05T13:28:34.799Z

Link: CVE-2026-18945

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T06:17:38.120

Modified: 2026-08-13T06:17:38.120

Link: CVE-2026-18945

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T08:00:04Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-285

    Improper Authorization