Executive brief
A security vulnerability was identified in the Live sales notification for WooCommerce plugin, which is used to display real-time purchase alerts on e-commerce websites. The flaw could allow unauthorized individuals to access information that should be restricted due to improper access controls. Although the specific CVE identifier was later rejected or withdrawn, the underlying issue affected versions up to 2.3.60.
Technical details
The Live sales notification for WooCommerce plugin for WordPress was found to have a missing authorization vulnerability (CWE-862). This flaw stems from incorrectly configured access control security levels within the plugin's components. A remote, unauthenticated attacker could exploit this over the network to bypass intended restrictions and potentially access sensitive data or functionality. The vulnerability affects versions up to and including 2.3.60. Note: While the specific CVE-2026-27066 was rejected by the CNA, the historical record indicates the presence of this authorization bypass prior to the withdrawal.
Affected products
- PI Web Solution Live sales notification for WooCommerce <= 2.3.60
Timeline
- 2026-02-19: disclosed: Initial disclosure by Patchstack
- 2026-06-11: other: CVE ID rejected or withdrawn by the CVE Numbering Authority (CNA)