Vulnerabilities and security researches forlive-sales-notifications-for-woocommerce live-sales-notifications-for-woocommerce
Direction: descendingFeb 28, 2026
Live sales notification for WooCommerce, Fake sales notification for WooCommerce, Recent sales popup for WooCommerce # CVE-2026-27066
- CVE, Research URL
- Date
- Feb 19, 2026
- Research Description
- Missing Authorization vulnerability in PI Web Solution Live sales notification for WooCommerce live-sales-notifications-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Live sales notification for WooCommerce: from n/a through <= 2.3.46.
- Affected versions
-
max 2.3.46.
- Status
-
vulnerable
Dec 10, 2025
Live sales notification for WooCommerce, Fake sales notification for WooCommerce, Recent sales popup for WooCommerce # CVE-2025-12955
- CVE, Research URL
- Date
- Nov 18, 2025
- Research Description
- The Live sales notification for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.3.39. This is due to the "getOrders" function lacking proper authorization and capability checks when the plugin is configured to display recent order information. This makes it possible for unauthenticated attackers to extract sensitive customer information including buyer first names, city, state, country, purchase time and date, and product details.
- Affected versions
-
max 2.3.40.
- Status
-
vulnerable