wc_rb_get_fresh_nonce of the component AJAX Handler. This manipulation of the argument nonce_name causes missing authorization.This vulnerability appears as CVE-2026-3567. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.