Executive brief
The DEPART plugin for WordPress, which allows WooCommerce store owners to accept deposits and partial payments, contains a security flaw in its access control settings. An authenticated user, such as a customer, could potentially bypass intended restrictions to perform actions or access data they should not be authorized to see. This could lead to unauthorized modifications of payment settings or exposure of internal configuration details.
Technical details
A Missing Authorization (CWE-862) vulnerability exists in the Andy Ha DEPART (depart-deposit-and-part-payment-for-woo) plugin for WordPress through version 1.0.7. The flaw stems from incorrectly configured access control security levels within the plugin's logic. A remote attacker with low-level authentication (such as a subscriber or customer) can exploit this to bypass authorization checks. Depending on the specific endpoint affected, this could allow for unauthorized data retrieval or modification of plugin settings. The issue is addressed in version 1.0.8.
Affected products
- Andy Ha DEPART (Deposit and Part Payment for WooCommerce) <= 1.0.7
Timeline
- 2026-04-08: disclosed
- 2026-04-08: advisory
- 2026-04-08: patched: Fixed in version 1.0.8