Description
The Japanized for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `order` REST API endpoint in all versions up to, and including, 2.7.17. This makes it possible for unauthenticated attackers to mark any WooCommerce order as processed/completed.
Problem types
Product status
* (semver)
Timeline
| 2025-12-13: | Discovered |
| 2025-12-18: | Vendor Notified |
| 2026-01-08: | Disclosed |
Credits
Md. Moniruzzaman Prodhan
References
www.wordfence.com/...-f235-472c-b751-96ac9838b27f?source=cve
plugins.trac.wordpress.org/...dy/class-wc-paidy-endpoint.php