CVE-2026-86851
MEDIUM
NVD
CVSS Score
6.5
Severity
MEDIUM
Published
Oct 09, 2026
Vendor
unknown
Description
The Livees Checkout WordPress plugin through 7.0.2 does not perform any capability, nonce or order-key check before acting on request parameters on the order confirmation page, allowing unauthenticated users to change the status of arbitrary orders, store arbitrary data and notes on them, and recover their order keys.