CVE-2026-3589Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The WooCommerce WordPress plugin from versions 5.4.0 to 10.5.2 does not properly handle batch requests, which could allow unauthenticated users to make a logged in admin call non store/WC REST endpoints, and create arbitrary admin users via a CSRF attack for example.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-352

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 5d ago at 3 mentions (2026-03-06); latest day: 1
  • 8 total mentions across 6 days

Deep dive

Activity timeline8 mentions / 6d
01223Mentions · 2026-03-06: 3Mentions · 2026-03-11: 1Mentions · 2026-03-27: 1Mentions · 2026-03-30: 1Mentions · 2026-06-28: 1Mentions · 2026-09-07: 1Patch / Workaround · 2026-03-30: 1Patch / Workaround · 2026-06-28: 1Patch / Workaround · 2026-09-07: 1Technical Details · 2026-03-06: 2Technical Details · 2026-03-11: 1Technical Details · 2026-03-30: 1Technical Details · 2026-06-28: 1Technical Details · 2026-09-07: 103-0603-1103-2703-3006-2809-07
Signal classification3 categories
Disclosure
337.5%
Patch
337.5%
General
225.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-063
Disclosure3
2026-03-111
General1
2026-03-271
General1
2026-03-301
Patch1
2026-06-281
Patch1
2026-09-071
Patch1
Full discourse8 posts
  • TheyamLolzz@TheyamLolzz
    General

    @grok @elonmusk @xai Of course~>first leaks: • Gmail dumps (24h, TLS-only) • WordPress+Node.js +CVE-2026-3589 • Self-service exports without OAuth2 scopes dc_identifier+oorg_code links directly to DUO (oorg10148), UWV (oorg10016) Fake transparency feeding real profiling. @elonmusk @xai @grok https://t.co/phpwrEx4eA

    Post summary

    The tweet references a CVE and some leak contexts but provides no concrete technical details, PoC, exploitation evidence, or mitigation guidance.

    1000069
    64 followersView on X
  • Dominik@GronskiDev
    Patch

    Krytyczna luka w WooCommerce. CVE-2026-3589. CSRF w batch API. Wersje 5.4.0 do 10.5.2. Atak jest prosty. Właściciel sklepu klika spreparowany link, atakujący dostaje konto administratora. Bez tokena, bez potwierdzenia. Skanery botowe mają już exploit w bazie. Kwestia tygodni, zanim polecą masowo po polskim WordPressie. Sprawdzcie wersję Woo w kokpicie. Aktualizacja do 10.5.3 albo nowszej dziś, nie za tydzień. Jeśli używacie SLA z aktualizacjami automatycznymi, to jest ten moment kiedy się okazuje czy dostawca faktycznie patchuje na produkcji, czy tylko fakturuje.

    Post summary

    A critical CSRF flaw in WooCommerce (CVE‑2026‑3589) enables attackers to gain admin rights via a crafted link; the afflicted versions are 5.4.0‑10.5.2, and the recommended fix is to update to 10.5.3 or later, while bots already have an exploit but no documented active attacks.

    0000037
    18 followersView on X
  • Donweb Media@DonwebMedia
    Patch

    Si manejás un WooCommerce, esto te interesa: hay un bug CSRF (CVE-2026-3589) que no se soluciona solo con actualizar. En esta guía te explico cómo parchearlo en 10 minutos y fortalecer la seguridad. Acá: https://seguridadenwordpress.com/parchear-cve-2026-woocommerce-guia-admins/

    Post summary

    The post warns of a CSRF vulnerability (CVE-2026-3589) in WooCommerce that cannot be fixed by a simple update and offers a 10‑minute patch guide to remediate it.

    0000035
    4 followersView on X
  • Quttera - eCommerce Security@MNovofastovsky
    Patch

    #WooCommerce security alert: CVE-2026-3589 Affects versions 5.4 through 10.5.2 and could allow admin account creation if a logged-in admin is tricked into clicking a malicious link. Update to 10.5.3 immediately. Advisory: https://developer.woocommerce.com/2026/03/02/store-api-vulnerability-patched-in-woocommerce-5-4/ #WooCommerce #WordPress #WordPressSecurity #CyberSecurity #WebSecurity #CVE #CSRF #eCommerceSecurity #Malware

    Post summary

    WooCommerce warns of a CSRF flaw (CVE‑2026‑3589) that could let admins create accounts through malicious links, and urges users to upgrade to version 10.5.3 immediately via the provided advisory.

    0000095
    38 followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-3589 (CVSS:7.5, HIGH) is Awaiting Analysis. The WooCommerce WordPress plugin from versions 5.4.0 to 10.5.2 does not properly handle batch requests, which could allo..https://nvd.nist.gov/vuln/detail/CVE-2026-3589 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-3589 affecting WooCommerce plugin versions 5.4.0 to 10.5.2, noting its severity and a batch‑request handling flaw, but it provides no evidence of exploitation, PoC, or mitigation information.

    0000033
    172 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3589 The WooCommerce WordPress plugin from versions 5.4.0 to 10.5.2 does not properly handle batch requests, which could allow unauthenticated users to make a logged in admi… https://www.cve.org/CVERecord?id=CVE-2026-3589

    Post summary

    The excerpt announces a vulnerability in WooCommerce (CVE‑2026‑3589) that allows unauthenticated users to exploit improper batch request handling, potentially leading to admin access.

    00000116
    56.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3589 - WooCommerce < 10.5.3 - Arbitrary Admin User Creation via CSRF Intel Report: http://cyberbivash.blogspot.com/2026/03/cve-2026-3589-woocommerce-1053.html

    Post summary

    The post announces the CVE-2026-3589 vulnerability in WooCommerce versions below 10.5.3, which allows attackers to create arbitrary admin users via CSRF.

    0000035
    343 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3589 WooCommerce REST API Vulnerability Enables Unauthenticated Admin U... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3589 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet references a newly disclosed WooCommerce REST API vulnerability (CVE‑2026‑3589) but provides no further detail on exploitation, patches, or technical specifics.

    0000040
    4.0K followersView on X

Explore more