CVE-2026-3589
HIGHWooCommerce 5.4.0-10.5.2 - Unauthenticated Cross-Site Request Forgery via Batch Request Handling
Title source: llmDescription
The WooCommerce WordPress plugin from versions 5.4.0 to 10.5.2 does not properly handle batch requests, which could allow unauthenticated users to make a logged in admin call non store/WC REST endpoints, and create arbitrary admin users via a CSRF attack for example.
References (2)
Core 2
Core References
Third Party Advisory exploit
vdb-entry
technical-description
https://wpscan.com/vulnerability/53ded097-274d-4850-82ee-620bf02f7553/
Various Sources technical-description
https://developer.woocommerce.com/2026/03/02/store-api-vulnerability-patched-in-woocommerce-5-4/
Scores
CVSS v3
7.5
EPSS
0.0013
EPSS Percentile
2.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-352
Status
published
Published
Mar 06, 2026
Tracked Since
Mar 06, 2026