Impact
The WordPress WooCommerce Order Details plugin contains a missing authorization flaw that permits unauthorized users to access order detail pages, exposing sensitive customer and transaction information. This bypasses intended access controls, potentially allowing attackers to view or manipulate order details and compromise privacy and business integrity.
Affected Systems
The flaw targets the vanquish WooCommerce Order Details plugin versions up to and including 3.1. Any WordPress site that has installed this plugin with a version number no higher than 3.1 is potentially exposed and should audit its installations accordingly.
Risk and Exploitability
The CVSS score of 7.5 highlights a high‑severity risk, while the EPSS score indicates a very low exploitation probability at present. The vulnerability is not currently listed in the CISA KEV catalog. Attackers could exploit the flaw without prior authentication because the denial of authorization checks is inherently unauthenticated. Given the straightforward exploit path, sites hosting the affected plugin should prioritize mitigation.
OpenCVE Enrichment