Impact
The WPC Order Tip for WooCommerce plugin, before version 3.3.1, fails to enforce authorization or verify nonces in one of its reporting features. This oversight allows any unauthenticated user to fetch sensitive order information from the store, including billing names, order IDs, statuses, fee amounts, and dates. The weakness enables a complete disclosure of customer order details without any access controls, exposing confidential data to potential attackers.
Affected Systems
WPC Order Tip for WooCommerce WordPress plugin, versions older than 3.3.1.
Risk and Exploitability
The vulnerability is immediately exploitable by unauthenticated actors because the plugin does not protect the reporting endpoint. An attacker only needs to know or discover the URL to retrieve the data directly. The EPSS score of <1% indicates a low probability of exploitation in the wild, but the lack of authentication combined with the exposure of sensitive order data suggests a serious potential impact. The CVSS score of 7.5 classifies it as high severity, and it is not listed in CISA's KEV catalog, yet the confidentiality impact remains severe.
OpenCVE Enrichment