Description
The WP Helper Premium WordPress plugin before 4.7.6 does not verify the order key when rendering its custom order confirmation page or when handling the related AJAX actions, allowing unauthenticated users to view other customers' order details, including personal information, as well as change the state of arbitrary orders.

Exploitation requires WooCommerce to be active and the WP Helper Premium WordPress plugin before 4.7.6's optional order confirmation page module to be enabled.
Published: 2026-08-13
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WP Helper Premium WordPress plugin before version 4.7.6 fails to verify an order key when rendering a custom order confirmation page or when processing related Ajax actions, enabling unauthenticated users to access detailed order information and modify the status of arbitrary orders. This flaw results in the disclosure of personal customer data and the potential alteration of order states, compromising both confidentiality and integrity of transactional data.

Affected Systems

The vulnerability affects installations of the WP Helper Premium plugin where the optional order confirmation page module is enabled and WooCommerce is active. The flaw applies to all plugin versions prior to 4.7.6; no specific patch version list is provided. Site administrators should verify the plugin version and confirm that WooCommerce is present.

Risk and Exploitability

Because the flaw is exploitable without authentication and requires only that WooCommerce and the order confirmation module be active, the risk level is high. The CVSS score of 8.2 reflects a severe threat, while the EPSS score of <1% indicates a low probability of exploitation; the vulnerability is not currently listed in CISA’s KEV catalog. The likely attack vector is unauthenticated external access to order confirmation URLs or Ajax endpoints; based on the description, it is inferred that remote, web-based exploitation is possible with no special privileges.

Generated by OpenCVE AI on August 13, 2026 at 19:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update WP Helper Premium to version 4.7.6 or later to gain the order key validation fix
  • If the plugin cannot be updated immediately, temporarily disable the optional order confirmation page module or remove access to related Ajax endpoints until the patch is applied
  • Implement additional access controls or WAF rules to restrict unauthenticated access to order-related endpoints as a temporary protective measure

Generated by OpenCVE AI on August 13, 2026 at 19:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-285

Thu, 13 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-285

Thu, 13 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The WP Helper Premium WordPress plugin before 4.7.6 does not verify the order key when rendering its custom order confirmation page or when handling the related AJAX actions, allowing unauthenticated users to view other customers' order details, including personal information, as well as change the state of arbitrary orders. Exploitation requires WooCommerce to be active and the WP Helper Premium WordPress plugin before 4.7.6's optional order confirmation page module to be enabled.
Title WP Helper Premium < 4.7.6 - Unauthenticated Order Data Disclosure and Order Manipulation via Missing Order Key Validation
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-13T14:12:10.242Z

Reserved: 2026-08-05T13:28:34.799Z

Link: CVE-2026-18945

cve-icon Vulnrichment

Updated: 2026-08-13T14:04:49.987Z

cve-icon NVD

Status : Deferred

Published: 2026-08-13T06:17:38.120

Modified: 2026-08-26T16:30:52.723

Link: CVE-2026-18945

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T20:00:03Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key