5.3
CVE-2025-14073
- EPSS 0.23%
- Veröffentlicht 01.08.2026 09:16:57
- Zuletzt bearbeitet 29.09.2026 14:10:00
- Erkennungen
WooCommerce PayPal Payments <= 3.3.2 - Unauthenticated Sensitive Information Disclosure
WooCommerce PayPal Payments <= 3.3.2 - Unauthenticated Sensitive Information Disclosure
The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information Disclosure due to an Insecure Direct Object Reference in all versions up to, and including, 3.3.2 via the `enqueue_paypal_insights_script_on_order_received()` function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to obtain sensitive order information including order keys, which can then be leveraged to access full customer billing details (name, email, phone, address) via the WooCommerce Store API within a 10-minute grace period after order creation.
Mögliche Gegenmaßnahme
WooCommerce PayPal Payments: Update to version 3.4.0, or a newer patched version
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellerwoocommerce
≫
Produkt
WooCommerce PayPal Payments
Default Statusunaffected
Version <=
3.3.2
Version
0
Status
affected
VulnDex Vulnerability Enrichment
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
WooCommerce PayPal Payments
Version
*-3.3.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.23% | 0.142 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@wordfence.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-639 Authorization Bypass Through User-Controlled Key
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
https://plugins.trac.wordpress.org/browser/woocommerce-paypal-payments/tags/3.3.0/modules/ppcp-axo/src/AxoModule.php#L362
https://plugins.trac.wordpress.org/changeset/3458079/woocommerce-paypal-payments/trunk/modules/ppcp-axo/src/AxoModule.php
https://plugins.trac.wordpress.org/changeset?old_path=%2Fwoocommerce-paypal-payments/tags/3.3.2&new_path=%2Fwoocommerce-paypal-payments/tags/3.4.0
https://www.wordfence.com/threat-intel/vulnerabilities/id/a2919bbc-c4c2-4b52-90ec-2471218cd7d1?source=cve
https://www.wordfence.com/threat-intel/vulnerabilities/id/a2919bbc-c4c2-4b52-90ec-2471218cd7d1