Unauthenticated Bypass Vulnerability in Pre-Orders for WooCommerce by WordPress
CVE-2026-84849
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 3 September 2026
What is CVE-2026-84849?
An unauthenticated bypass vulnerability exists in versions of Pre-Orders for WooCommerce up to 2.3, allowing attackers to exploit the system without authentication. This flaw can enable unauthorized access to sensitive functionalities, posing a significant risk to stores relying on this plugin. It's crucial for users to update to the latest version and apply necessary patches to safeguard their online transactions.
Affected Version(s)
Pre-Orders for WooCommerce <= 2.3