CVE-2026-49059: WordPress Facebook for WooCommerce plugin <= 3.7.0 - Open Redirection vulnerability
Published May 27, 2026
·Updated
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Facebook Facebook for WooCommerce allows Phishing.
This issue affects Facebook for WooCommerce: from n/a through 3.7.0.
Affected Software
1 affected component
Facebook Facebook for WooCommerce<=3.7.0
Event History
May 27, 2026
CVE Published
via MITRE·02:33 PM
Data Sourced
via MITRE·02:33 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-49059?
The severity of CVE-2026-49059 is classified as medium with a score of 4.7.
2
How do I fix CVE-2026-49059?
To fix CVE-2026-49059, upgrade the Facebook for WooCommerce plugin to a version greater than 3.7.0.
3
What is the impact of CVE-2026-49059?
CVE-2026-49059 allows for open redirection to untrusted sites, which can be exploited for phishing attacks.
4
Which versions are affected by CVE-2026-49059?
CVE-2026-49059 affects all versions of Facebook for WooCommerce from n/a up to and including 3.7.0.
5
What type of vulnerability is CVE-2026-49059?
CVE-2026-49059 is classified as an Open Redirection vulnerability.