CVE-2026-32576: WordPress Faktur Pro for WooCommerce plugin <= 3.2.2 - Insecure Direct Object References (IDOR) vulnerability
Published Oct 6, 2026
·Updated
Authorization Bypass Through User-Controlled Key vulnerability in ZWEISCHNEIDER Faktur Pro for WooCommerce woorechnung allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Faktur Pro for WooCommerce: from n/a through 3.2.2.
Affected Software
1 affected component
ZWEISCHNEIDER Faktur Pro for WooCommerce<=3.2.2
Event History
Oct 6, 2026
CVE Published
via MITRE·05:14 AM
Data Sourced
via MITRE·05:14 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vector and privileges indicate that exploitation is possible over the network by an attacker with low-level privileges. No user interaction is required.
2
What is the likely impact of successful exploitation?
The provided CVSS vector indicates high confidentiality impact, with no integrity or availability impact. This is consistent with unauthorized access to customer-related data through insecure object references.
3
Are installations running version 3.2.1 affected?
Yes. The affected version range explicitly includes Faktur Pro for WooCommerce version 3.2.1 and earlier.