MEDIUM
CVE-2026-56013
CVSS
6.5
Description
Unauthenticated Insecure Direct Object References (IDOR) in License Manager for WooCommerce <= 3.0.15 versions.
Summary dbcve.org
Unauthenticated IDOR vulnerability in License Manager for WooCommerce plugin versions 3.0.15 and below allows attackers to access or modify license data without proper authorization due to missing access control validation on object references.
Mitigation
Update License Manager for WooCommerce to the latest version beyond 3.0.15 to include patched access control mechanisms.
Weakness (CWE)
CWE-639
Authorization Bypass (IDOR)
EPSS Score
0.33%
Probability of exploitation in next 30 days
26.6th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.