Medium 6.1
2026-05-01< 2.6.7
CVE-2024-13362
Minimum safe version
2.6.8
Update to 2.6.8 or later to address 7 fixable vulnerabilities
CVE-2024-13362
CVE-2025-26933
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress WC Place Order Without Payment Plugin < 2.5.2 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress WC Place Order Without Payment plugin <= 2.1 - Sensitive Information Disclosure vulnerability
WordPress WC Place Order Without Payment plugin <= 2.1 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability