Executive brief
A security vulnerability exists in the Montonio for WooCommerce plugin, which is used by online stores to process payments and manage shipping. An unauthorized attacker can bypass security checks to perform actions that should be restricted to administrators. This could allow an attacker to interfere with order processing or modify store settings, potentially disrupting business operations and payment workflows.
Technical details
The Montonio for WooCommerce plugin for WordPress is vulnerable to broken access control due to missing authorization checks (CWE-862) in certain functions. An unauthenticated remote attacker can exploit this flaw to execute privileged actions without any prior authentication or user interaction. The vulnerability has a CVSS score of 7.5, primarily impacting integrity as attackers can modify data or settings they should not have access to. The issue is resolved in version 10.1.3.
Affected products
- Montonio Montonio for WooCommerce <= 10.1.2
Timeline
- 2026-05-16: other: Reported by researcher Niv Kochan
- 2026-06-02: patched: Version 10.1.3 released
- 2026-06-15: disclosed: NVD publication date