Junglewise Threat Intelligence

CVE-2026-49059: Facebook Facebook for WooCommerce open redirect

CVE-2026-49059 · Severity: medium · CVSS 4.7 · Published 2026-05-27

Vendors: Meta.

Executive brief

The Facebook for WooCommerce plugin, which connects WordPress e-commerce sites to Facebook services, contains a security flaw that allows for open redirects. An attacker can use a legitimate link from your website to trick users into visiting a malicious or fraudulent site. This is primarily used in phishing campaigns to steal user credentials or distribute malware by leveraging the trust associated with your domain.

Technical details

An open redirect vulnerability (CWE-601) exists in the Facebook for WooCommerce plugin for WordPress through version 3.7.0. The software fails to properly validate user-supplied input used in redirection targets, allowing a remote, unauthenticated attacker to craft a URL that redirects victims to an arbitrary external domain. Exploitation requires a user to click a specially crafted link. This flaw is typically leveraged in phishing campaigns to bypass security filters and lend credibility to malicious URLs. As of the advisory date, no official patch has been confirmed.

Affected products

  • Facebook Facebook for WooCommerce n/a through 3.7.0

Timeline

  • 2026-02-02: other: Reported by researcher timomangcut
  • 2026-05-27: advisory: Published by Patchstack
  • 2026-05-27: disclosed: NVD publication date

References

Related threats