Executive brief
Pre-Orders for WooCommerce is a WordPress plugin that manages product pre-order functionality in online stores. An unauthenticated attacker can bypass security checks in versions 2.3 and earlier, potentially allowing unauthorized access to pre-order features or data without proper login credentials.
Technical details
The Pre-Orders for WooCommerce plugin contains an unauthenticated bypass vulnerability that allows attackers to circumvent security checks without authentication. The vulnerability affects versions 2.3.1 and earlier. An attacker can exploit this via a network-based attack vector without requiring user interaction or elevated privileges, resulting in partial compromise of confidentiality and integrity. No official patch is currently available; users should update to a patched version when available or implement compensating controls.
Affected products
- Bright Plugins Pre-Orders for WooCommerce <=2.3.1
Timeline
- 2026-09-03: disclosed
- 2026-08-11: other: Reported by MoonFuji