Order Splitter for WooCommerce
Order Splitter for WooCommerce has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2025 and 2026; all 2 are fixed as of September 2026. Their average CVSS score is 5.4, and the most serious one scores 6.5 out of 10.
The most common weakness is Missing Authorization, behind 1 of the records (50%). Other recurring categories include SQL Injection.
Every one of the 2 issues recorded for Order Splitter for WooCommerce has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Order Splitter for WooCommerce is installed on roughly 300 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2025-31089Order Splitter for WooCommerce <= 5.3.0 - Authenticated (Subscriber+) SQL Injection
Read the full analysisVulnerability Records

Order Splitter for WooCommerce
Author
Fahad Mahmood
Author: Fahad Mahmood Project URI: http://androidbubble.com/blog/wordpress/plugins/woo-order-splitter WooCommerce is an awesome eCommerce plugin that allows you to sell anything and if you want to sell products that are not on stock yet, but you’re sure that you’ll have them soon in stock again? So Order Splitter for WooCommerce is a solution for you as you can create a rule for those items. All of the upcoming items can go in a separate orders section/status. It enables you to split, consolidate, clone, your crowd/combined/bulk orders using intelligent rules. After activation there will be a Split icon in wp-admin > WooCommerce > orders list page within the order actions. Splits all order metadata and product data across into the new order ID. Order is created and a note is left in the new order of the older order ID for future reference. Order status is then set on hold awaiting admin to confirm payment. Tags woocommerce, pending payments, failed, processing, completed, cancelled, refunded How to use this plugin? License This WordPress plugin is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 2 of the License, or any later version. This WordPress plugin is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details. You should have received a copy of the GNU General Public License along with this WordPress plugin. If not, see http://www.gnu.org/licenses/gpl-2.0.html.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C