← WordPress Vulnerabilities
WordPress security by component

Deposits and Partial Payments for WooCommerce

Deposits and Partial Payments for WooCommerce (advanced-partial-payment-or-deposit-for-woocommerce) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 5.3.

Plugin slug: advanced-partial-payment-or-deposit-for-woocommerce

CVE-2026-27378: WooCommerce Deposits exposes an unauthenticated protected operation

Deposits and Partial Payments for WooCommerce through 3.1.0 lacks authorization on an operation reachable without authentication. The CNA vector requires no user interaction and rates integrity impact as low. The authoritative export does not identify the endpoint, action, parameter, order object, or change an attacker can make.

PublishedSep 11, 2026
Known safe version4.0.1
Published vulnerabilities for advanced-partial-payment-or-deposit-for-woocommerce
Safe version
Sep 11, 2026 CVE-2026-27378
WooCommerce Deposits exposes an unauthenticated protected operation
Deposits and Partial Payments for WooCommerce through 3.1.0 lacks authorization on an operation reachable without authentication. The CNA vector requires no user interaction and rates integrity impact as low. The authoritative export does not identify the endpoint, action, parameter, order object, or change an attacker can make.
4.0.1
CVE5.3
NVDPending