PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-56013 myCred CVE debrief

CVE-2026-56013 is a medium-severity vulnerability in License Manager for WooCommerce versions up to 3.0.15. The vulnerability allows unauthenticated attackers to access sensitive information due to an insecure direct object reference (IDOR) issue. This vulnerability was made public on June 25, 2026, and last modified on June 29, 2026. The CVSS score for this vulnerability is 6.5. The vendor for this product is listed as Unknown Vendor. More information can be found on the official CVE record and NVD detail pages.

Vendor
myCred
Product
License Manager for WooCommerce
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-25
Original CVE updated
2026-06-29
Advisory published
2026-06-25
Advisory updated
2026-06-29

Who should care

Defenders of WooCommerce installations using License Manager for WooCommerce versions up to 3.0.15 should prioritize patching this vulnerability. Attackers can exploit this IDOR vulnerability to access sensitive information without authentication. Security teams should review their inventory of WooCommerce installations and ensure that all instances are updated to a version beyond 3.0.15.

Technical summary

CVE-2026-56013 is an unauthenticated Insecure Direct Object References (IDOR) vulnerability in License Manager for WooCommerce versions up to 3.0.15. The vulnerability has a CVSS score of 6.5 and a CVSS severity of MEDIUM. The vulnerability allows attackers to access sensitive information without authentication. The Common Weakness Enumeration (CWE) associated with this vulnerability is CWE-639. The official CVE record and NVD detail pages provide additional information.

Defensive priority

Defenders should prioritize patching WooCommerce installations using License Manager for WooCommerce versions up to 3.0.15. Review inventory and update to a version beyond 3.0.15.

Recommended defensive actions

  • Review WooCommerce installations for License Manager for WooCommerce versions up to 3.0.15.
  • Update License Manager for WooCommerce to a version beyond 3.0.15.
  • Monitor for potential exploitation attempts.
  • Verify that no sensitive information is exposed due to this vulnerability.
  • Consider implementing additional security measures to protect against IDOR vulnerabilities.

Evidence notes

The CVE-2026-56013 vulnerability was made public on June 25, 2026, and last modified on June 29, 2026. The vulnerability has a CVSS score of 6.5 and a CVSS severity of MEDIUM. The CWE associated with this vulnerability is CWE-639. The official CVE record and NVD detail pages provide additional information.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-56013 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-56013

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-56013 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-56013

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.