CVE-2026-25443: WordPress Fraud Prevention For Woocommerce plugin <= 2.3.3 - Arbitrary Content Deletion vulnerability
Missing Authorization vulnerability in Dotstore Fraud Prevention For Woocommerce woo-blocker-lite-prevent-fake-orders-and-blacklist-fraud-customers allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fraud Prevention For Woocommerce: from n/a through <= 2.3.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25443?
CVE-2026-25443 is classified as a high severity vulnerability due to its potential for unauthorized content deletion.
How do I fix CVE-2026-25443?
To fix CVE-2026-25443, upgrade the DotStore Fraud Prevention for WooCommerce plugin to version 2.3.4 or later.
What type of vulnerability is CVE-2026-25443?
CVE-2026-25443 is an arbitrary content deletion vulnerability caused by missing authorization controls.
Who is affected by CVE-2026-25443?
CVE-2026-25443 affects users of the DotStore Fraud Prevention for WooCommerce plugin version 2.3.3 and earlier.
Can CVE-2026-25443 lead to a data breach?
Yes, CVE-2026-25443 can potentially lead to a data breach due to unauthorized deletion of content.