Impact
The WPC Order Tip for WooCommerce plugin, before version 3.3.1, fails to enforce authorization or verify nonces in one of its reporting features. This oversight allows any unauthenticated user to fetch sensitive order information from the store, including billing names, order IDs, statuses, fee amounts, and dates. The weakness enables a complete disclosure of customer order details without any access controls, exposing confidential data to potential attackers.
Affected Systems
WPC Order Tip for WooCommerce WordPress plugin, versions older than 3.3.1.
Risk and Exploitability
The vulnerability is immediately exploitable by unauthenticated actors. Because the plugin does not protect the reporting endpoint, an attacker only needs to know or discover the URL and can retrieve the data directly. The EPSS score is not available, but the absence of any authentication requirement coupled with the exposure of sensitive order data suggests high exploitation likelihood. The CVSS score is not provided, and the vulnerability is not currently listed in CISA's KEV catalog, yet the impact on confidentiality remains severe.
OpenCVE Enrichment