AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-18603

MEDIUM · CVSS 6.5 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-08-09 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The PiWeb Cancel order / Refund request feature in the WooCommerce WordPress plugin prior to version 1.3.4.34 lacks proper authorization and ownership checks, enabling unauthenticated users to access and disclose the contents of other customers' orders. Additionally, this vulnerability allows attackers to manipulate a logged-in user's cart through crafted links. WordPress site administrators using this plugin should prioritize immediate updates to mitigate potential data exposure and unauthorized cart manipulation.

CVE
CVE-2026-18603
Severity
MEDIUM
CVSS
6.5
EPSS
0.22%
WordPress

Original NVD Description

The PiWeb Cancel order / Refund request for WooCommerce WordPress plugin before 1.3.4.34 does not have authorization or ownership checks when adding the contents of a previous order to the cart, allowing unauthenticated users to disclose the contents of other customers' orders, as well as to clear and repopulate a logged in user's cart via a crafted link.