Impact
An Insecure Direct Object Reference flaw exists in all releases of Faktur Pro for WooCommerce up to and including 3.2.1. The flaw allows an attacker to manipulate order or invoice identifiers present in URLs or request payloads and retrieve any customer’s order data. This exposes sensitive financial and personal information, potentially violating privacy regulations and giving attackers leverage for fraud or phishing.
Affected Systems
The affected product is the Faktur Pro for WooCommerce plugin, developed by ZWEISCHNEIDER. All installations running version 3.2.1 or older are vulnerable; no specific sub‑versions are distinguished in the CVE data.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation. The CVE description does not state whether an attacker must be authenticated; it is inferred that the vulnerability may be exploitable by an authenticated customer, but the exact attack vector is unspecified. Because the flaw can expose confidential order details, it poses a significant risk to confidentiality and may support further fraudulent activity.
OpenCVE Enrichment