CVE-2026-3589: Automattic Woocommerce

High severity, CVSS 7.5. EPSS: 0.2% chance of exploitation in the next 30 days.

The WooCommerce WordPress plugin from versions 5.4.0 to 10.5.2 does not properly handle batch requests, which could allow unauthenticated users to make a logged in admin call non store/WC REST endpoints, and create arbitrary admin users via a CSRF attack for example.

Affected products

  • Automattic Woocommerce: from 5.4.0, before 5.4.4 (fixed in 5.4.4); from 5.5.0, before 5.4.5 (fixed in 5.4.5); from 5.6.0, before 5.6.3 (fixed in 5.6.3); from 5.7.0, before 5.7.3 (fixed in 5.7.3); from 5.8.0, before 5.8.2 (fixed in 5.8.2); from 5.9.0, before 5.9.2 (fixed in 5.9.2); …

Published 2026-03-06. Last modified 2026-06-17.