MEDIUM

CVE-2026-56013

2026-06-25 CVSS v3.1
CVSS
6.5

Description

Unauthenticated Insecure Direct Object References (IDOR) in License Manager for WooCommerce <= 3.0.15 versions.

Summary dbcve.org

Unauthenticated IDOR vulnerability in License Manager for WooCommerce plugin versions 3.0.15 and below allows attackers to access or modify license data without proper authorization due to missing access control validation on object references.

Mitigation

Update License Manager for WooCommerce to the latest version beyond 3.0.15 to include patched access control mechanisms.

Weakness (CWE)

CWE-639 Authorization Bypass (IDOR)

EPSS Score

0.33%
Probability of exploitation in next 30 days
26.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE