Executive brief
The License Manager for WooCommerce plugin, which helps online stores manage and distribute software license keys, contains a security flaw that allows unauthorized users to access or modify data. An attacker could exploit this to interact with the database or access sensitive information without needing a password. This could lead to the unauthorized distribution of license keys or disruption of the store's licensing operations.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in the License Manager for WooCommerce plugin (versions <= 3.0.15) due to insufficient authorization checks on user-controlled keys. An unauthenticated remote attacker can exploit this by manipulating input parameters to access or modify objects they are not authorized to interact with. This bypasses intended access controls and can lead to unauthorized database interaction or access to sensitive files. The issue is addressed in version 3.0.16.
Affected products
- myCred License Manager for WooCommerce <= 3.0.15
Timeline
- 2026-04-29: other: Reported by researcher dodoh4t
- 2026-06-19: advisory: Patchstack advisory published
- 2026-06-25: disclosed: NVD publication date
- 2026-06-19: patched: Version 3.0.16 released to address the vulnerability