PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-56013 myCred CVE debrief

CVE-2026-56013 is a medium-severity vulnerability in License Manager for WooCommerce versions up to 3.0.15. The vulnerability allows unauthenticated attackers to access sensitive information due to an insecure direct object reference (IDOR) issue. This vulnerability was made public on June 25, 2026, and last modified on June 29, 2026. The CVSS score for this vulnerability is 6.5. The vendor for this product is listed as Unknown Vendor. More information can be found on the official CVE record and NVD detail pages.

Vendor
myCred
Product
License Manager for WooCommerce
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-25
Original CVE updated
2026-06-29
Advisory published
2026-06-25
Advisory updated
2026-06-29

Who should care

Defenders of WooCommerce installations using License Manager for WooCommerce versions up to 3.0.15 should prioritize patching this vulnerability. Attackers can exploit this IDOR vulnerability to access sensitive information without authentication. Security teams should review their inventory of WooCommerce installations and ensure that all instances are updated to a version beyond 3.0.15.

Technical summary

CVE-2026-56013 is an unauthenticated Insecure Direct Object References (IDOR) vulnerability in License Manager for WooCommerce versions up to 3.0.15. The vulnerability has a CVSS score of 6.5 and a CVSS severity of MEDIUM. The vulnerability allows attackers to access sensitive information without authentication. The Common Weakness Enumeration (CWE) associated with this vulnerability is CWE-639. The official CVE record and NVD detail pages provide additional information.

Defensive priority

Defenders should prioritize patching WooCommerce installations using License Manager for WooCommerce versions up to 3.0.15. Review inventory and update to a version beyond 3.0.15.

Recommended defensive actions

  • Review WooCommerce installations for License Manager for WooCommerce versions up to 3.0.15.
  • Update License Manager for WooCommerce to a version beyond 3.0.15.
  • Monitor for potential exploitation attempts.
  • Verify that no sensitive information is exposed due to this vulnerability.
  • Consider implementing additional security measures to protect against IDOR vulnerabilities.

Evidence notes

The CVE-2026-56013 vulnerability was made public on June 25, 2026, and last modified on June 29, 2026. The vulnerability has a CVSS score of 6.5 and a CVSS severity of MEDIUM. The CWE associated with this vulnerability is CWE-639. The official CVE record and NVD detail pages provide additional information.

Official resources

This article is AI-assisted and based on the supplied source corpus.