WordPress security by component
Deposits and Partial Payments for WooCommerce
Deposits and Partial Payments for WooCommerce (advanced-partial-payment-or-deposit-for-woocommerce) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 5.3.
Plugin slug:
advanced-partial-payment-or-deposit-for-woocommerceLatest vulnerability
CVE-2026-27378: WooCommerce Deposits exposes an unauthenticated protected operation
Deposits and Partial Payments for WooCommerce through 3.1.0 lacks authorization on an operation reachable without authentication. The CNA vector requires no user interaction and rates integrity impact as low. The authoritative export does not identify the endpoint, action, parameter, order object, or change an attacker can make.
| Safe version |
|
||
|---|---|---|---|
| Sep 11, 2026 |
CVE-2026-27378
WooCommerce Deposits exposes an unauthenticated protected operation
Deposits and Partial Payments for WooCommerce through 3.1.0 lacks authorization on an operation reachable without authentication. The CNA vector requires no user interaction and rates integrity impact as low. The authoritative export does not identify the endpoint, action, parameter, order object, or change an attacker can make.
|
4.0.1 |
CVE5.3
NVDPending
|