CVE-2026-73399: WordPress Flutterwave WooCommerce plugin <= 3.3.0 - Broken Authentication vulnerability
Published Aug 18, 2026
·Updated
Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions.
Affected Software
1 affected component
woocommerce-flutterwave<=3.3.0
Event History
Aug 18, 2026
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are exposed to this vulnerability?
Sites running Flutterwave WooCommerce version 3.3.0 or earlier are identified as affected. The issue is remotely reachable and does not require authentication or user interaction.
2
What does an attacker need to exploit the issue?
The provided severity vector indicates that exploitation has low attack complexity and can be performed over the network without privileges or user interaction. Successful exploitation may affect integrity and availability, while no confidentiality impact is indicated.