CVE-2026-18357: CWE-200 Information Exposure in WPC Order Tip for WooCommerce
CVE-2026-18357 is an information exposure vulnerability in the WPC Order Tip for WooCommerce WordPress plugin versions before 3.3.1. The flaw arises because the plugin does not perform authorization or nonce checks in one of its reporting features. This allows unauthenticated attackers to access sensitive order data of any customer, including billing names, order IDs, statuses, fee amounts, and order dates.
AI Analysis
Technical Summary
The WPC Order Tip for WooCommerce plugin prior to version 3.3.1 contains a CWE-200 information exposure vulnerability due to missing authorization and nonce verification in a reporting feature. This security gap enables unauthenticated users to retrieve sensitive customer order information such as billing names, order identifiers, order statuses, fee amounts, and order dates without proper access controls.
Potential Impact
Unauthenticated attackers can access sensitive customer order data from the affected WooCommerce stores. This exposure of personally identifiable information and order details can lead to privacy violations and potential misuse of customer data. There is no indication of active exploitation in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the reporting features of the plugin and monitor for updates from the vendor. Avoid exposing the vulnerable reporting functionality to unauthenticated users.
CVE-2026-18357: CWE-200 Information Exposure in WPC Order Tip for WooCommerce
Description
CVE-2026-18357 is an information exposure vulnerability in the WPC Order Tip for WooCommerce WordPress plugin versions before 3.3.1. The flaw arises because the plugin does not perform authorization or nonce checks in one of its reporting features. This allows unauthenticated attackers to access sensitive order data of any customer, including billing names, order IDs, statuses, fee amounts, and order dates.
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The WPC Order Tip for WooCommerce plugin prior to version 3.3.1 contains a CWE-200 information exposure vulnerability due to missing authorization and nonce verification in a reporting feature. This security gap enables unauthenticated users to retrieve sensitive customer order information such as billing names, order identifiers, order statuses, fee amounts, and order dates without proper access controls.
Potential Impact
Unauthenticated attackers can access sensitive customer order data from the affected WooCommerce stores. This exposure of personally identifiable information and order details can lead to privacy violations and potential misuse of customer data. There is no indication of active exploitation in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the reporting features of the plugin and monitor for updates from the vendor. Avoid exposing the vulnerable reporting functionality to unauthenticated users.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-07-30T08:20:25.072Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a781a2fbf8831d5391fff17
Added to database: 08/09/2026, 06:11:59 UTC
Last enriched: 08/09/2026, 06:32:37 UTC
Last updated: 08/09/2026, 06:37:50 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.