{"api_version":"1","generated_at":"2026-10-09T16:53:06+00:00","cve":"CVE-2026-86851","urls":{"html":"https://cve.report/CVE-2026-86851","api":"https://cve.report/api/cve/CVE-2026-86851.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-86851","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-86851"},"summary":{"title":"Livees Checkout 6.8 - 7.0.2 - Unauthenticated Order Status Change, Order Note Injection & Order Key Disclosure","description":"The Livees Checkout WordPress plugin through 7.0.2 does not perform any capability, nonce or order-key check before acting on request parameters on the order confirmation page, allowing unauthenticated users to change the status of arbitrary orders, store arbitrary data and notes on them, and recover their order keys.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-10-09 12:17:12","updated_at":"2026-10-09 15:17:18"},"problem_types":["CWE-862","CWE-862 Missing Authorization","CWE-862 CWE-862 Missing Authorization"],"metrics":[{"version":"3.1","source":"contact@wpscan.com","type":"Secondary","score":"6.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"6.5","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","data":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","version":"3.1"}}],"references":[{"url":"https://wpscan.com/vulnerability/c9730831-54a3-4307-94c9-e994337a943c/","name":"https://wpscan.com/vulnerability/c9730831-54a3-4307-94c9-e994337a943c/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-86851","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86851","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"Livees Checkout","version":"affected 6.8 7.0.2 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Naoki Kawahigashi","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-86851","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-10-09T14:49:35.606886Z","version":"2.0.3"},"type":"ssvc"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-862","description":"CWE-862 Missing Authorization","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-10-09T15:00:19.018Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"collectionURL":"https://wordpress.org/plugins","defaultStatus":"unknown","product":"Livees Checkout","vendor":"Unknown","versions":[{"lessThanOrEqual":"7.0.2","status":"affected","version":"6.8","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Naoki Kawahigashi"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The Livees Checkout WordPress plugin through 7.0.2 does not perform any capability, nonce or order-key check before acting on request parameters on the order confirmation page, allowing unauthenticated users to change the status of arbitrary orders, store arbitrary data and notes on them, and recover their order keys."}],"metrics":[{"cvssV3_1":{"baseScore":6.5,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","version":"3.1"}}],"problemTypes":[{"descriptions":[{"description":"CWE-862 Missing Authorization","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-10-09T11:03:34.280Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/c9730831-54a3-4307-94c9-e994337a943c/"}],"source":{"discovery":"EXTERNAL"},"title":"Livees Checkout 6.8 - 7.0.2 - Unauthenticated Order Status Change, Order Note Injection & Order Key Disclosure","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-86851","datePublished":"2026-10-09T11:03:34.280Z","dateReserved":"2026-09-08T14:58:01.540Z","dateUpdated":"2026-10-09T15:00:19.018Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-10-09 12:17:12","lastModifiedDate":"2026-10-09 15:17:18","problem_types":["CWE-862","CWE-862 Missing Authorization","CWE-862 CWE-862 Missing Authorization"],"metrics":{"cvssMetricV31":[{"source":"contact@wpscan.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-10-09T14:49:35.606886Z","id":"CVE-2026-86851","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"86851","Ordinal":"1","Title":"Livees Checkout 6.8 - 7.0.2 - Unauthenticated Order Status Chang","CVE":"CVE-2026-86851","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"86851","Ordinal":"1","NoteData":"The Livees Checkout WordPress plugin through 7.0.2 does not perform any capability, nonce or order-key check before acting on request parameters on the order confirmation page, allowing unauthenticated users to change the status of arbitrary orders, store arbitrary data and notes on them, and recover their order keys.","Type":"Description","Title":"Livees Checkout 6.8 - 7.0.2 - Unauthenticated Order Status Chang"}]}}}