CVE-2025-15484 impacts the Order Notification for WooCommerce WordPress plugin before version 3.6.3. This critical vulnerability allows unauthenticated requests to bypass WooCommerce's permission checks, granting full read and write access to sensitive store resources such as products, coupons, and customer information. The attack vector is remote and unauthenticated, leading to a severe potential impact on data integrity and confidentiality. While no public exploit code is currently available and it is not listed on the CISA KEV catalog, the vulnerability has received minimal community discussion to date.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Unknown | Order Notification For WooCommerce | >= 0, < 3.6.3CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.