Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical0
High1
Medium1
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2026-02-19

CVE-2026-27066 - Live sales notification for WooCommerce Plugin

Missing Authorization vulnerability in PI Web Solution Live sales notification for WooCommerce live-sales-notifications-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Live sales notification for WooCommerce: from n/a through

PLUGIN Live sales notification for WooCommerce

CVE-2026-27066

MEDIUM CVSS 5.3 2026-02-19
Threat Entry Updated 2025-11-18

CVE-2025-12955 - Live Sales Notification For Woocommerce Plugin

The Live sales notification for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.3.39. This is due to the "getOrders" function lacking proper authorization and capability checks when the plugin is configured to display recent order information. This makes it possible for unauthenticated attackers to extract sensitive customer information including buyer first names, city, state, country, purchase time and date, and product details.

PLUGIN Live Sales Notification For Woocommerce

CVE-2025-12955

HIGH CVSS 7.5 2025-11-18
Scroll to top