All verified exploits

CVE-2025-15484 WooCommerce Store Takeover via Permission Bypass

Deterministic critical WordPress Added cve-verified-cve-2025-15484

Detects the Order Notification for WooCommerce plugin (woc-order-alert) before version 3.6.2 which overrides WooCommerce's REST API permission checks with a blanket '__return_true' filter. Any unauthenticated attacker can read customer data, modify products, create fraudulent coupons, and manipulate orders via the WooCommerce REST API.

Related WordPress exploits

Is your app exploitable through CVE-2025-15484?

Scan your domain free