PT-2026-69273 · WordPress · Order Tip For Woocommerce
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WPC Order Tip for WooCommerce versions prior to 3.3.1
Description
A reporting feature fails to perform authorization or nonce checks. A nonce is a unique token used to protect against cross-site request forgery. This flaw allows unauthenticated attackers to retrieve sensitive order data from any customer, including billing names, order IDs, order statuses, fee amounts, and order dates.
Recommendations
Update WPC Order Tip for WooCommerce to version 3.3.1 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Order Tip For Woocommerce