Impact
The Track Orders for WooCommerce plugin, before version 1.2.7, allows an unauthenticated attacker to retrieve billing details such as a customer’s name, email address, phone number, postal address, and order history simply by providing an email address. The flaw arises because the plugin does not verify that the requester owns the order before exposing billing data, constituting an information exposure vulnerability rooted in improper access control.
Affected Systems
This weakness affects the WordPress plugin Track Orders for WooCommerce on installations running any version prior to 1.2.7. Vulnerability is tied to the plugin’s public-facing order tracking functionality and is exploitable on any WordPress site that uses the affected plugin without additional access restrictions.
Risk and Exploitability
The absence of authentication or ownership checks means that any user with knowledge of a target email address can harvest personal data. While there is no reported exploitation probability (EPSS is not available) and the vulnerability is not listed in CISA’s KEV catalog, the potential to expose sensitive customer information warrants high risk. Attackers could leverage the exposed data for phishing, identity theft or targeted social engineering. The weakness is reachable through the plugin’s email parameter endpoint, making it a likely attack vector for automated or manual enumeration of customer accounts.
OpenCVE Enrichment