CVE-2025-15484: Unknown Order Notification For Woocommerce

Critical severity, CVSS 9.1. EPSS: 0.2% chance of exploitation in the next 30 days.

The Order Notification for WooCommerce WordPress plugin before 3.6.3 overrides WooCommerce's permission checks to grant full access to all unauthenticated requests, enabling complete read/write access to store resources like products, coupons, and customers.

Affected products

  • Unknown Order Notification For Woocommerce: before 3.6.3 (fixed in 3.6.3)

Published 2026-04-01. Last modified 2026-10-07.