Detects the Order Notification for WooCommerce plugin (woc-order-alert) before version 3.6.2 which overrides WooCommerce's REST API permission checks with a blanket '__return_true' filter. Any unauthenticated attacker can read customer data, modify products, create fraudulent coupons, and manipulate orders via the WooCommerce REST API.
Is your app exploitable through CVE-2025-15484?
Scan your domain free