CVE-2025-1284
Woocommerce Automatic Order Printing | ( Formerly WooCommerce Google Cloud Print) <= 4.1 - Insecure Direct Object Reference to Authenticated (Subscriber+) Order Information Disclosure
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Woocommerce Automatic Order Printing | ( Formerly WooCommerce Google Cloud Print) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1 via the xc_woo_printer_preview AJAX action due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view other user's invoices and orders which can contain sensitive information.
El complemento WooCommerce Automatic Order Printing | (anteriormente WooCommerce Google Cloud Print) para WordPress es vulnerable a una Referencia Directa a Objetos Insegura en todas las versiones hasta la 4.1 incluida, mediante la acción AJAX xc_woo_printer_preview debido a la falta de validación en una clave controlada por el usuario. Esto permite que atacantes autenticados, con acceso de suscriptor o superior, vean las facturas y pedidos de otros usuarios, que pueden contener información confidencial.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2025-02-13 CVE Reserved
- 2025-04-23 CVE Published
- 2025-04-24 CVE Updated
- 2025-05-26 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-639: Authorization Bypass Through User-Controlled Key
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://codecanyon.net/item/woocommerce-google-cloud-print/21129093 | ||
https://www.wordfence.com/threat-intel/vulnerabilities/id/6f593dce-4b56-46c0-becd-75fd16f165a8?source=cve |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Xpertsclub Search vendor "Xpertsclub" | Woocommerce Automatic Order Printing | ( Formerly WooCommerce Google Cloud Print) Search vendor "Xpertsclub" for product "Woocommerce Automatic Order Printing | ( Formerly WooCommerce Google Cloud Print)" | <= 4.1 Search vendor "Xpertsclub" for product "Woocommerce Automatic Order Printing | ( Formerly WooCommerce Google Cloud Print)" and version " <= 4.1" | en |
Affected
|