---
id: CVE-2026-18357
title: >-
  The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does not
  perform authorisation or nonce checks in one of its reporting features,
  allowing unauthenticated attackers to retrieve sensitive order data belonging
  to any custome…
summary: >-
  The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does not
  perform authorisation or nonce checks in one of its reporting features,
  allowing unauthenticated attackers to retrieve sensitive order data belonging
  to any custome…
severity: none
published: '2026-08-09'
updated: '2026-08-09'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18357'
references:
  - url: 'https://wpscan.com/vulnerability/ff675d0a-03f2-4309-830c-0e96e1d95a62/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00434
epssPercentile: 0.34984
ingestedAt: '2026-08-09T15:33:38.293Z'
---

## Overview

The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does not perform authorisation or nonce checks in one of its reporting features, allowing unauthenticated attackers to retrieve sensitive order data belonging to any customer of the store, such as billing names, order IDs and statuses, fee amounts and order dates.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
