WooCommerce

Guide tag · 12 matching pages

Wordpress Alert: Webhook signature validation failures

An integration accepts incoming webhook data without verifying its signature. A forged notification may trigger order or account actions.

Wordpress Alert: Webhook endpoint authorization bypass

An incoming webhook route trusts a request without authenticating its sender. External callers may trigger automation or data changes.

Wordpress Alert: Unauthorized price changes

A product endpoint accepts edits from a user without catalog rights. Products may be sold at unintended prices.

Wordpress Alert: Subscription ownership bypass

A customer can change another customer's subscription identifier in a request. Billing or subscription settings may be altered across accounts.

Wordpress Alert: Payment status spoofing

A payment integration accepts an unverified completion signal. An unpaid order may appear paid or be fulfilled.

Wordpress Alert: Order record access bypass

A customer can view or alter an order that is not theirs. Names, addresses, and purchase details may leak.

Wordpress Alert: Malicious nulled themes or plugins

A pirated package contains hidden code or a modified updater. It may create a backdoor or steal data.

Wordpress Alert: Gift-card balance manipulation

A gift-card extension trusts balance changes from an unauthorized request. Store credit may be created or spent improperly.

Wordpress Alert: Customer data disclosure

An API or plugin returns customer records to an unauthorized caller. Personal and purchase information may be exposed.

Wordpress Alert: Coupon creation without authorization

A low-privilege account can create or modify coupons. An attacker may issue discounts that the store never approved.

Wordpress Alert: Checkout-field upload vulnerabilities

A checkout extension accepts files without suitable type or authorization checks. Customer-supplied files may become a code or data exposure route.

Wordpress Alert: Cart total manipulation

An extension trusts a client-submitted total instead of recalculating server-side. A buyer may be charged less than the actual order value.