CVE-2025-15484Disclosure

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Order Notification for WooCommerce WordPress plugin before 3.6.3 overrides WooCommerce's permission checks to grant full access to all unauthenticated requests, enabling complete read/write access to store resources like products, coupons, and customers.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Patch: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-04-01); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-01: 2Mentions · 2026-04-16: 1Technical Details · 2026-04-01: 2Technical Details · 2026-04-16: 104-0104-16
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-012
Disclosure2
2026-04-161
Patch1
Full discourse3 posts
  • Quttera - eCommerce Security@MNovofastovsky
    Patch

    CVE-2025-15484 is a serious WooCommerce risk. The Order Notification for WooCommerce plugin before 3.6.3 can bypass permission checks and give unauthenticated attackers read/write access to products, coupons, and customer-related store data. Update fast. https://nvd.nist.gov/vuln/detail/CVE-2025-15484 Protect your store and stay malware free 👉 https://quttera.com/wordpress-malware-scanner #WooCommerce #WordPressSecurity #CVE #eCommerceSecurity #WordPress #MalwareProtection #SilentRisk

    Post summary

    The post announces a serious WooCommerce vulnerability that allows unauthenticated attackers to read and write sensitive store data, urging for immediate updates but providing no exploit code or detailed patch guidance.

    00000355
    39 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2025-15484 - Critical The Order Notification for WooCommerce WordPress plugin before 3.6.3 overrides WooCommerce's permission checks to grant full access to all unauthenticated requests, enabling complete rea... https://www.thehackerwire.com/vulnerability/CVE-2025-15484/ https://t.co/Vnu1kQDAEb

    Post summary

    The post announces CVE‑2025‑15484 in the WooCommerce Order Notification plugin, noting that versions before 3.6.3 allow unauthenticated users full access, but it offers no PoC, exploit code, patch, or evidence of active exploitation.

    00000218
    163 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-15484 The Order Notification for WooCommerce WordPress plugin before 3.6.3 overrides WooCommerce's permission checks to grant full access to all unauthenticated requests, … https://www.cve.org/CVERecord?id=CVE-2025-15484

    Post summary

    A disclosure of CVE-2025-15484 details how the WooCommerce Order Notification plugin (v<3.6.3) allows unauthenticated users to bypass permission checks and gain full access.

    00000118
    56.9K followersView on X

Explore more