Impact
The WP Helper Premium WordPress plugin before version 4.7.6 fails to verify an order key when rendering a custom order confirmation page or when processing related Ajax actions, enabling unauthenticated users to access detailed order information and modify the status of arbitrary orders. This flaw results in the disclosure of personal customer data and the potential alteration of order states, compromising both confidentiality and integrity of transactional data.
Affected Systems
The vulnerability affects installations of the WP Helper Premium plugin where the optional order confirmation page module is enabled and WooCommerce is active. The flaw applies to all plugin versions prior to 4.7.6; no specific patch version list is provided. Org admin should check the plugin version and ensure WooCommerce is present.
Risk and Exploitability
Because the flaw is exploitable without authentication and requires only that WooCommerce and the order confirmation module be active, the risk level is high. No CVSS rating is listed, and EPSS is unavailable, but the exposure of customer data and the ability to manipulate orders suggest significant impact. The vulnerability is not currently listed in CISA’s KEV catalog. The likely attack vector is unauthenticated external access to order confirmation URLs or Ajax endpoints; based on the description, it is inferred that remote, web‑based exploitation is possible with no special privileges.
OpenCVE Enrichment