Impact
The vulnerability exists in the Ni WooCommerce Sales Report WordPress plugin versions before 4.2.0. Due to missing authentication or authorization checks on the report‑printing route that accepts a 'btn_print' parameter, an attacker can trigger the routine without needing to log in. The plugin then exposes WooCommerce order details, including billing and shipping addresses, and customer contact information. Collectively, this allows an external user to view sensitive order data for any order, or to search the store’s orders by customer name or email address, effectively leaking personal and financial information.
Affected Systems
This flaw affects installations of the Ni WooCommerce Sales Report WordPress plugin with a version less than 4.2.0. The affected vendor is listed as Unknown:Ni WooCommerce Sales Report, and the product is the Ni WooCommerce Sales Report plugin for WordPress. No specific sub‑products or operating systems are mentioned; any WordPress site that has the plugin installed and versions older than 4.2.0 is impacted.
Risk and Exploitability
The vulnerability is exploitable through a’s print endpoint, which is reachable on all sites that expose the admin area or the frontend. The EPSS score indicates a very low but non‑zero probability of exploitation, and the vulnerability is not included in CISA’s KEV catalog, suggesting no known widespread exploitation. However, the lack of authentication combined with the sensitive nature of the data makes theSS score is published, exact impact figures are unavailable, but the potential for data exposure across potentially flaw for affected sites.
OpenCVE Enrichment