CVE-2026-49072: WordPress WooCommerce Anti-Fraud plugin <= 7.2.6 - Broken Access Control vulnerability
Published Jun 17, 2026
·Updated
Unauthenticated Broken Access Control in WooCommerce Anti-Fraud <= 7.2.6 versions.
Affected Software
1 affected component
WooCommerce WooCommerce Anti-Fraud<=7.2.6
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WooCommerce Anti-Fraud pluginto a version that resolves this vulnerability.Fixed in 7.2.7
Event History
Jun 17, 2026
CVE Published
via MITRE·09:51 AM
Data Sourced
via MITRE·09:51 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:20 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-49072?
The severity of CVE-2026-49072 is classified as medium with a score of 6.5.
2
How does CVE-2026-49072 affect WooCommerce Anti-Fraud users?
CVE-2026-49072 allows unauthenticated users to exploit broken access control in versions 7.2.6 and below.
3
How do I fix CVE-2026-49072?
To fix CVE-2026-49072, update the WooCommerce Anti-Fraud plugin to version 7.2.7 or later.
4
Is CVE-2026-49072 a high-risk vulnerability?
CVE-2026-49072 is considered medium risk, with a potential impact score of 40.
5
What type of vulnerability is CVE-2026-49072?
CVE-2026-49072 is categorized as a Broken Access Control vulnerability.