WordPress Plugin Vulnerabilities

WP Helper Premium < 4.7.6 - Unauthenticated Order Data Disclosure and Order Manipulation via Missing Order Key Validation

Description

The plugin does not verify the order key when rendering its custom order confirmation page or when handling the related AJAX actions, allowing unauthenticated users to view other customers' order details, including personal information, as well as change the state of arbitrary orders.

Exploitation requires WooCommerce to be active and the plugin's optional order confirmation page module to be enabled.

Proof of Concept

Affects Plugins

Fixed in 4.7.6

References

Classification

Type
IDOR
CWE
CVSS

Miscellaneous

Original Researcher
Farid Narimanov
Submitter
Farid Narimanov
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-08-11 (about 24 days ago)
Added
2026-08-11 (about 23 days ago)
Last Updated
2026-08-11 (about 23 days ago)

Other