WordPress Plugin Vulnerabilities
Livees Checkout 6.8 - 7.0.2 - Unauthenticated Order Status Change, Order Note Injection & Order Key Disclosure
Description
The plugin does not perform any capability, nonce or order-key check before acting on request parameters on the order confirmation page, allowing unauthenticated users to change the status of arbitrary orders, store arbitrary data and notes on them, and recover their order keys.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
NO AUTHORISATION
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Naoki Kawahigashi
Submitter
Naoki Kawahigashi
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-10-06 (about 2 days ago)
Added
2026-09-29 (about 9 days ago)
Last Updated
2026-09-29 (about 9 days ago)