Impact
The Live Sales Notification for WooCommerce plugin is vulnerable due to a missing authorization check in the getOrders function. This flaw allows any user to retrieve customer order details—including first names, location, purchase time, and product information—without authentication. The weakness is classified as a Missing Authorization (CWE-862) and results in unauthorized disclosure of sensitive customer data.
Affected Systems
This issue affects the RajeshSingh520 PiWeb Live Sales Notification for WooCommerce plugin for WordPress, versions up to and including 2.3.39. The vulnerability is present in all installations of these versions where the recent order display feature is enabled. Upgrading to versions newer than 2.3.39 removes the flaw.
Risk and Exploitability
The CVSS score of 7.5 indicates a high level of risk, while the EPSS score of less than 1% suggests a very low probability of exploitation at this time. The flaw is not currently listed in CISA's KEV catalog. Exploitation would require sending an unauthenticated request to the getOrders endpoint, which is reachable over the network once the plugin is installed. The attack is simple and does not require elevated privileges, making it a potentially attractive vector for attackers seeking direct data exposure.
OpenCVE Enrichment