Executive brief
Japanized For WooCommerce is a WordPress plugin that adapts the WooCommerce e-commerce platform for the Japanese market. A security flaw in versions 2.9.12 and earlier allows unauthenticated individuals to bypass access controls. This could potentially allow unauthorized users to perform actions or modify settings that should be restricted to administrators, impacting the integrity of the online store.
Technical details
A broken access control vulnerability exists in the Japanized For WooCommerce plugin for WordPress (versions <= 2.9.12) due to missing authorization (CWE-862). The flaw allows an unauthenticated remote attacker to execute functions or actions that should be restricted to higher-privileged users. The vulnerability is exploitable over the network without user interaction. Attackers can potentially modify site data or disrupt service availability. The issue is resolved in version 2.9.13.
Affected products
- shohei.tanaka Japanized For WooCommerce <= 2.9.12
Timeline
- 2026-04-29: other: Reported by researcher HaiND
- 2026-06-29: disclosed: Vulnerability published by Patchstack and NVD
- 2026-06-29: patched: Patch released in version 2.9.13