Orders Chat for WooCommerce

Orders Chat for WooCommerce has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.

The most common weakness is Missing Authorization, behind 1 of the records (100%).

The one issue recorded for Orders Chat for WooCommerce has a vendor fix available, so running the current release closes it.

All of these findings were reported by Powpy. Orders Chat for WooCommerce is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
4.3/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Orders Chat for WooCommerce vulnerabilities before they are exploited.

Highest severity on recordCVSS 4.3CVE-2025-49356

Orders Chat for WooCommerce <= 2.0.0 - Missing Authorization

Read the full analysis

Vulnerability Records

1 records
Orders Chat for WooCommerce banner
Latestv4.0.0

Orders Chat for WooCommerce

Mykola Lukin

Author

Mykola Lukin

5.0(2)
100/100
Last Updated
2026-09-04 (9d ago)
Active Installs
100+
Downloads
2,779
Requires WP
6.5+
Requires PHP
7.4+
Tested up to
WP 7.1
Created
2024-02-20 (3y ago)
Requires Plugins
woocommerce

Orders Chat gives every WooCommerce order its own private conversation. Customers write from My Account, your team answers from one inbox inside WooCommerce, and the whole story of the order stays in one place: the questions, the replies, the status changes and the read receipts. No third-party chat widget and no separate helpdesk. Questions about an order are answered where the order lives. See it in action For your customers A Messages tab in My Account lists every order conversation, and each order has its own chat. Guests who checked out without an account get the conversation on the order-received page, protected by the order key, and every notification email links back to it. Read receipts show when the store has seen a message, and an email arrives when the store replies. The chat is built from your theme’s own fonts, colors and buttons, so it looks native on classic and block themes alike. Pick one of the built-in palettes if you prefer. For your team The Messenger page under WooCommerce shows every conversation with the latest message, order status and unread counts. Search by order number, name or email, filter to unread, and reply without leaving the page. Unread badges on the Orders list open a chat modal right there, and the full conversation also lives on the order edit screen. Schedule a message for later, choose whether the customer is emailed, mark messages unread, delete them. Decide which roles can read and answer. Replies can be signed with your store name instead of personal names. Messages that send themselves Scheduled messages: delivery reminders, review requests and check-ins go out on their own, even when nobody is logged in. Order updates: status changes and customer-facing order notes are posted into the conversation. Purchase messages: give a product a message, and every buyer receives it when the order is placed or paid. Notifications that don’t flood Both sides are emailed about new messages through regular WooCommerce emails. Digests bundle everything that arrived within a delay you choose, with the messages quoted and a link back to the conversation. Free and premium The free version has the complete conversation flow: chats, notifications, scheduled and automatic messages, the Messenger page, the Orders list modal and the order screen. Premium adds file attachments: customers send photos and documents, your team attaches media library files, everything is stored privately and served only to the people in the conversation. Upgrade from the plugin’s pricing page or on u2code.com; the license key unlocks attachments in place and keeps every conversation. Developers REST API, hooks for every event, overridable templates and shortcodes for any page. See the documentation and the developer guide.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C