CVE-2026-86851 PUBLISHED

Livees Checkout 6.8 - 7.0.2 - Unauthenticated Order Status Change, Order Note Injection & Order Key Disclosure

Assigner: WPScan
Reserved: 08.09.2026 Published: 09.10.2026 Updated: 09.10.2026

The Livees Checkout WordPress plugin through 7.0.2 does not perform any capability, nonce or order-key check before acting on request parameters on the order confirmation page, allowing unauthenticated users to change the status of arbitrary orders, store arbitrary data and notes on them, and recover their order keys.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
CVSS Score: 6.5

Product Status

Vendor Unknown
Product Livees Checkout
Versions Default: unknown
  • affected from 6.8 to 7.0.2 (incl.)

Credits

  • Naoki Kawahigashi finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE