CVE-2026-84849: WordPress Pre-Orders for WooCommerce plugin <= 2.3 - Bypass Vulnerability vulnerability
Published Sep 3, 2026
·Updated
Unauthenticated Bypass Vulnerability in Pre-Orders for WooCommerce <= 2.3 versions.
Affected Software
1 affected component
WordPress Pre-Orders for WooCommerce<=2.3
Event History
Sep 3, 2026
CVE Published
via MITRE·04:31 PM
Data Sourced
via MITRE·04:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or other prior privileges to exploit it. The vector is network-based and does not require user interaction.
2
What security impact is indicated?
The supplied severity vector indicates low impact to confidentiality and integrity, with no indicated availability impact. It is rated medium severity with a CVSS score of 6.5.
3
Which plugin versions are identified as affected?
The affected range is Pre-Orders for WooCommerce version 2.3 and earlier. The provided data does not identify a fixed version or workaround.