Description
Customer Insecure Direct Object References (IDOR) in Faktur Pro for WooCommerce <= 3.2.1 versions.
Published: 2026-10-06
Score: 6.5 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized access to customer order data
Action: Immediate Patch
AI Analysis

Impact

An Insecure Direct Object Reference flaw exists in all releases of Faktur Pro for WooCommerce up to and including 3.2.1. The flaw allows an attacker to manipulate order or invoice identifiers present in URLs or request payloads and retrieve any customer’s order data. This exposes sensitive financial and personal information, potentially violating privacy regulations and giving attackers leverage for fraud or phishing.

Affected Systems

The affected product is the Faktur Pro for WooCommerce plugin, developed by ZWEISCHNEIDER. All installations running version 3.2.1 or older are vulnerable; no specific sub‑versions are distinguished in the CVE data.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation. The CVE description does not state whether an attacker must be authenticated; it is inferred that the vulnerability may be exploitable by an authenticated customer, but the exact attack vector is unspecified. Because the flaw can expose confidential order details, it poses a significant risk to confidentiality and may support further fraudulent activity.

Generated by OpenCVE AI on October 6, 2026 at 07:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Faktur Pro for WooCommerce to the latest official release, which contains the IDOR fix.
  • If an upgrade is not immediately possible, restrict unauthenticated access to order URLs by configuring the plugin’s access controls or applying .htaccess rules.
  • Review user role permissions in WordPress and ensure that only staff roles granted to order management can view invoice data.
  • Consider enabling two‑factor authentication for all WordPress administrator accounts and monitor access logs for abnormal order retrieval attempts.

Generated by OpenCVE AI on October 6, 2026 at 07:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 05:30:00 +0000

Type Values Removed Values Added
Description Customer Insecure Direct Object References (IDOR) in Faktur Pro for WooCommerce <= 3.2.1 versions.
Title WordPress Faktur Pro for WooCommerce plugin <= 3.2.1 - Insecure Direct Object References (IDOR) vulnerability
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-06T05:14:45.697Z

Reserved: 2026-03-12T11:12:52.971Z

Link: CVE-2026-32576

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T06:17:00.500

Modified: 2026-10-06T06:17:00.500

Link: CVE-2026-32576

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T07:30:19Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key