Back to blog
e-commercevulnerabilitiesWooCommerce

E-commerce: why 70% of online stores are vulnerable to privilege escalation

Published on 2026-02-286 min readFlorian

French e-commerce underestimates the risk

Flaw 1: Client-side price manipulation

If the price is sent from frontend to payment API, users can modify the amount.

Flaw 2: Cross-customer order access

Sequential order IDs = enumerate and view all customers' orders.

Flaw 3: Stock bypass

Negative quantities, simultaneous requests, stock manipulation via API.

Flaw 4: Weak customer authentication

Predictable password reset, no 2FA, non-expiring sessions.

Flaw 5: Vulnerable WooCommerce plugins

Plugins adding unauthenticated REST endpoints. We regularly find public CSV export endpoints.

Related articles

Three adjacent analyses to keep exploring the same attack surface.

Sources

Written by Florian
Reviewed on 2026-02-28

Editorial analysis based on official vendor, project, and regulator documentation.

Related services

If this topic maps to a real risk in your stack, these are the most relevant CleanIssue audits.

Need an external review of your HR SaaS?

Share your product, stack, and client context. We will come back with the right review scope.

Discuss your audit