Junglewise Threat Intelligence

CVE-2026-49072: OPMC WooCommerce Anti-Fraud broken access control

CVE-2026-49072 · Severity: medium · CVSS 6.5 · Published 2026-06-17

Executive brief

WooCommerce Anti-Fraud is a WordPress plugin designed to detect and prevent fraudulent transactions on e-commerce sites. A security flaw in versions 7.2.6 and earlier allows unauthenticated individuals to bypass security checks and perform actions they should not be authorized to do. This could lead to unauthorized changes to site settings or interference with fraud detection operations, potentially impacting the integrity of the store's security measures.

Technical details

The WooCommerce Anti-Fraud plugin for WordPress suffers from a broken access control vulnerability (CWE-862) in versions up to and including 7.2.6. The flaw stems from a lack of proper authorization or nonce validation on certain functions, allowing an unauthenticated remote attacker to execute actions that should be restricted to higher-privileged users. According to the CVSS vector, the impact is limited to low integrity and availability impacts, suggesting an attacker can modify certain data or disrupt specific plugin features without full site takeover. The issue is resolved in version 7.2.7.

Affected products

  • OPMC WooCommerce Anti-Fraud <= 7.2.6

Timeline

  • 2026-05-27: other: Vulnerability reported by Austin Ginder
  • 2026-06-08: advisory: Patchstack advisory published
  • 2026-06-17: disclosed: CVE published to NVD
  • 2026-06-17: patched: Patch confirmed available in version 7.2.7

References