CVE-2026-86851: Livees Checkout 6.8 - 7.0.2 - Unauthenticated Order Status Change, Order Note Injection & Order Key Disclosure
Published Oct 9, 2026
·Updated
The Livees Checkout WordPress plugin through 7.0.2 does not perform any capability, nonce or order-key check before acting on request parameters on the order confirmation page, allowing unauthenticated users to change the status of arbitrary orders, store arbitrary data and notes on them, and recover their order keys.
Affected Software
1 affected component
Livees Checkout>=6.8<=7.0.2
Event History
Oct 9, 2026
CVE Published
via MITRE·11:03 AM
Data Sourced
via MITRE·11:03 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Any unauthenticated remote user can exploit it. No account, capability, nonce, or existing order key is required.
2
What order data can an attacker affect or obtain?
An attacker can change the status of arbitrary orders, store arbitrary data and notes on those orders, and recover order keys.
3
Which plugin versions are affected?
Livees Checkout versions through 7.0.2 are affected. The provided information does not identify a fixed version.