cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forlive-sales-notifications-for-woocommerce live-sales-notifications-for-woocommerce

Direction: descending
Feb 28, 2026

Live sales notification for WooCommerce, Fake sales notification for WooCommerce, Recent sales popup for WooCommerce # CVE-2026-27066

CVE, Research URL

CVE-2026-27066

Date
Feb 19, 2026
Research Description
Missing Authorization vulnerability in PI Web Solution Live sales notification for WooCommerce live-sales-notifications-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Live sales notification for WooCommerce: from n/a through <= 2.3.46.
Affected versions
max 2.3.46.
Status
vulnerable
Dec 10, 2025

Live sales notification for WooCommerce, Fake sales notification for WooCommerce, Recent sales popup for WooCommerce # CVE-2025-12955

CVE, Research URL

CVE-2025-12955

Date
Nov 18, 2025
Research Description
The Live sales notification for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.3.39. This is due to the "getOrders" function lacking proper authorization and capability checks when the plugin is configured to display recent order information. This makes it possible for unauthenticated attackers to extract sensitive customer information including buyer first names, city, state, country, purchase time and date, and product details.
Affected versions
max 2.3.40.
Status
vulnerable