Impact
A WordPress plugin for PayPal WooCommerce fails to validate the order key before exposing order data in JavaScript that is rendered on the front end. An unauthenticated user can learn the secret that protects each order by iterating sequential order identifiers, and then access billing and shipping details for that customer. The primary impact is the disclosure of personally identifiable information to anyone who can trigger the vulnerable endpoint.
Affected Systems
The vulnerability affects the Payment Plugins for PayPal WooCommerce WordPress plugin for any version prior to 2.0.26. Users running the plugin on their WooCommerce sites are at risk.
Risk and Exploitability
The CVSS score is 5.3, but the exploit is considered trivial: it requires only a web browser and access to the order‑pay URL. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be network, likely from any external host that can reach the site, because no authentication is required. Exploitation is straightforward and can be repeated via sequential order IDs.
OpenCVE Enrichment