Description
The OneClick Chat to Order plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.0.9. This is due to the plugin not properly verifying that a user is authorized to perform an action in the wa_order_number_save_number_field function. This makes it possible for authenticated attackers, with Editor-level access and above, to modify WhatsApp phone numbers used by the plugin, redirecting customer orders and messages to attacker-controlled phone numbers.
Published: 2026-02-19
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass
Action: Update Plugin
AI Analysis

Impact

The OneClick Chat to Order plugin for WordPress is affected by an unauthorized modification vulnerability (CWE-862). The plugin fails to verify that an authenticated user has permission to change phone number settings in the wa_order_number_save_number_field function. A malicious Editor or higher level user can alter the phone numbers used for WhatsApp orders, causing customer orders and communications to be redirected to attacker-controlled numbers. This flaw does not provide code execution but enables malicious modification of configuration data, potentially allowing fraud and loss of revenue.

Affected Systems

The vendor walterpimen publishes the OneClick Chat to Order plugin. Versions up to and including 1.0.9 are vulnerable. Updating to any release newer than 1.0.9 removes the verification issue.

Risk and Exploitability

The CVSS score is 2.7, indicating a low severity flaw. The EPSS score is less than 1%, implying a very low probability of exploitation in the wild, and it is not listed in the CISA KEV catalog. The likely attack vector is through the WordPress administrative interface where a user with Editor or higher capability can access plugin settings. Because the flaw requires prior authenticated access it is not exploitable by unauthenticated users, but any site where Editors have approval authority is at risk.

Generated by OpenCVE AI on April 20, 2026 at 20:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the OneClick Chat to Order plugin to a version newer than 1.0.9 that implements proper authorization checks.
  • If an upgrade is not immediately feasible, disable the plugin to prevent modification of phone numbers until a fix is applied.
  • Restrict Editor and higher roles from accessing the plugin settings page through custom capability adjustments or role management plugins.
  • Verify that all plugin settings changes are protected by WordPress nonces and capability checks before deployment.

Generated by OpenCVE AI on April 20, 2026 at 20:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 24 Feb 2026 02:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 19 Feb 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Walterpinem
Walterpinem oneclick Chat To Order
Wordpress
Wordpress wordpress
Vendors & Products Walterpinem
Walterpinem oneclick Chat To Order
Wordpress
Wordpress wordpress

Thu, 19 Feb 2026 05:00:00 +0000

Type Values Removed Values Added
Description The OneClick Chat to Order plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.0.9. This is due to the plugin not properly verifying that a user is authorized to perform an action in the wa_order_number_save_number_field function. This makes it possible for authenticated attackers, with Editor-level access and above, to modify WhatsApp phone numbers used by the plugin, redirecting customer orders and messages to attacker-controlled phone numbers.
Title OneClick Chat to Order <= 1.0.9 - Missing Authorization to Authenticated (Editor+) Plugin Settings Update
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Walterpinem Oneclick Chat To Order
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:17:02.176Z

Reserved: 2025-12-08T14:15:55.997Z

Link: CVE-2025-14270

cve-icon Vulnrichment

Updated: 2026-02-24T01:35:11.933Z

cve-icon NVD

Status : Deferred

Published: 2026-02-19T07:17:34.523

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-14270

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-20T21:00:12Z

Weaknesses