WP Helper Premium
WP Helper Premium (wp-helper-lite) is a WordPress plugin with 5 published CVE records in this archive. The latest tracked vulnerability was published Aug 13, 2026; the highest published CVSS base score is 8.2.
wp-helper-liteCVE-2026-18945: WP Helper order confirmation exposes PII and order-state actions
WP Helper Premium before 4.7.6, when WooCommerce and its optional custom order-confirmation module are enabled, resolves an attacker-supplied order-received ID without requiring the matching order key or order owner. A logged-out caller can view another order's billing name, email, phone, address, items and totals. Page-issued nonces also allowed related public AJAX actions, including whp_confirm_transfer and whp_cancel_order_expired, to move a pending order to on-hold or cancelled. Version 4.7.6 adds whp_thankyou_verify_order_access(), requiring the WooCommerce order key or authenticated order owner across the page and related actions. The order-ID discovery method and reporter proof of concept remain undisclosed until September 11.
| Safe version |
|
||
|---|---|---|---|
| Aug 13, 2026 |
CVE-2026-18945
WP Helper order confirmation exposes PII and order-state actions
WP Helper Premium before 4.7.6, when WooCommerce and its optional custom order-confirmation module are enabled, resolves an attacker-supplied order-received ID without requiring the matching order key or order owner. A logged-out caller can view another order's billing name, email, phone, address, items and totals. Page-issued nonces also allowed related public AJAX actions, including whp_confirm_transfer and whp_cancel_order_expired, to move a pending order to on-hold or cancelled. Version 4.7.6 adds whp_thankyou_verify_order_access(), requiring the WooCommerce order key or authenticated order owner across the page and related actions. The order-ID discovery method and reporter proof of concept remain undisclosed until September 11.
|
4.7.6 |
CVE8.2
NVDPending
|
| Apr 17, 2025 |
CVE-2025-24737
WP Helper Premium: A security weakness
WP Helper Premium is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Oct 10, 2024 |
CVE-2024-9065
WP Helper Premium: A security weakness
WP Helper Premium is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Apr 18, 2024 |
CVE-2024-32595
WP Helper Premium: Cross-site scripting
WP Helper Premium is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.1
NVDPending
|
| Nov 09, 2023 |
CVE-2023-46614
Wp Helper Lite: Cross-site request forgery
Wp Helper Lite is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD8.8
|