CVE-2026-27378: WordPress Deposits and Partial Payments for WooCommerce plugin <= 3.1.0 - Broken Access Control vulnerability
Published Sep 11, 2026
·Updated
Unauthenticated Broken Access Control in Deposits and Partial Payments for WooCommerce <= 3.1.0 versions.
Affected Software
1 affected component
wordpress/woocommerce-deposits-partial-payments<=3.1.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Deposits and Partial Payments for WooCommerce Pluginto a version that resolves this vulnerability.Fixed in 4.0.1
Event History
Sep 11, 2026
CVE Published
via MITRE·06:12 PM
Data Sourced
via MITRE·06:12 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is unauthenticated, so an attacker does not need a WordPress or WooCommerce account to attempt exploitation. The network attack vector indicates the affected site must be reachable over the network.
2
Which installations are affected?
Deposits and Partial Payments for WooCommerce versions 3.1.0 and earlier are affected. The provided data does not identify any configuration prerequisite or workaround for unpatched installations.