AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-18945

HIGH · CVSS 8.2 EPSS 0.19% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The WP Helper Premium WordPress plugin versions prior to 4.7.6 are vulnerable due to inadequate verification of order keys, which allows unauthenticated users to access and manipulate other customers' order details and personal information. This vulnerability can be exploited when WooCommerce is active and the optional order confirmation page module is enabled. WordPress site administrators using this plugin should prioritize immediate updates to mitigate potential data exposure and unauthorized order modifications.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-18945
Severity
HIGH
CVSS
8.2
EPSS
0.19%
WordPress

Original NVD Description

The WP Helper Premium WordPress plugin before 4.7.6 does not verify the order key when rendering its custom order confirmation page or when handling the related AJAX actions, allowing unauthenticated users to view other customers' order details, including personal information, as well as change the state of arbitrary orders. Exploitation requires WooCommerce to be active and the WP Helper Premium WordPress plugin before 4.7.6's optional order confirmation page module to be enabled.