PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-49072 OPMC CVE debrief

CVE-2026-49072 is a medium-severity vulnerability in the WooCommerce Anti-Fraud plugin. The vulnerability, which has a CVSS score of 6.5, allows unauthenticated broken access control. It was published on June 17, 2026, and last modified on the same day. The vendor and product information are not confirmed, but Patchstack has identified it as a potential issue. Users of the affected plugin versions should take immediate action to mitigate the risk.

Vendor
OPMC
Product
WooCommerce Anti-Fraud
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-17
Original CVE updated
2026-06-17
Advisory published
2026-06-17
Advisory updated
2026-06-17

Who should care

Administrators and security teams of WordPress installations using the WooCommerce Anti-Fraud plugin versions <= 7.2.6 should be aware of this vulnerability and take necessary actions to protect their sites.

Technical summary

The CVE-2026-49072 vulnerability has a CVSS vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L, indicating a medium-severity issue. It is categorized under CWE-862. The vulnerability allows unauthenticated broken access control in the WooCommerce Anti-Fraud plugin versions <= 7.2.6.

Defensive priority

medium

Recommended defensive actions

  • Update the WooCommerce Anti-Fraud plugin to a version greater than 7.2.6.
  • Restrict access to sensitive areas of the WordPress installation.
  • Monitor for suspicious activity on the site.
  • Implement additional security measures, such as two-factor authentication.
  • Regularly review and update plugins and themes.
  • Consider using a web application firewall (WAF).
  • Keep WordPress core, plugins, and themes up-to-date.

Evidence notes

The information provided is based on data from the National Vulnerability Database (NVD) and Patchstack. The CVE record was published on June 17, 2026, and last modified on the same day. The vendor and product information are not confirmed, but Patchstack has identified it as a potential issue.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-49072 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-49072

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-49072 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-49072

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.