SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-27378

MEDIUM · CVSS 5.3 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-09-11 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

WooCommerce versions up to 3.1.0 are vulnerable to unauthenticated broken access control, allowing unauthorized users to access and potentially manipulate deposit and partial payment functionalities. This could lead to financial discrepancies and unauthorized transactions. E-commerce operators using affected versions should prioritize remediation to safeguard their payment processes and customer data.

CVE
CVE-2026-27378
Severity
MEDIUM
CVSS
5.3
EPSS
0.21%

Original NVD Description

Unauthenticated Broken Access Control in Deposits and Partial Payments for WooCommerce <= 3.1.0 versions.