PT-2025-29987 · WordPress · Plugin Pengiriman Woocommerce Kurir Reguler

Ch4R0N

·

Published

2025-07-18

·

Updated

2025-07-22

·

CVE-2025-5816

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Plugin Pengiriman WooCommerce Kurir Reguler, Instan, Kargo – Biteship versions through 3.2.0
Description The Plugin Pengiriman WooCommerce Kurir Reguler, Instan, Kargo – Biteship for WordPress is susceptible to an Insecure Direct Object Reference issue. This flaw is due to a lack of validation on a user-controlled key within the get order detail() function. Authenticated attackers with Subscriber-level access or higher can exploit this to view order details belonging to other users.
Recommendations Update Plugin Pengiriman WooCommerce Kurir Reguler, Instan, Kargo – Biteship to a version later than 3.2.0.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-5816

Affected Products

Plugin Pengiriman Woocommerce Kurir Reguler