PT-2025-47284 · Unknown+1 · Woocommerce+1

Athiwat Tiprasaharn

·

Published

2025-11-18

·

Updated

2025-11-18

·

CVE-2025-12955

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Live sales notification for WooCommerce plugin for WordPress versions prior to 2.3.39
Description The Live sales notification for WooCommerce plugin for WordPress is affected by a missing authorization issue. The getOrders function does not have proper authorization and capability checks when configured to display recent order information. This allows unauthenticated attackers to extract sensitive customer information, including buyer first names, city, state, country, purchase time and date, and product details.
Recommendations Update to a version newer than 2.3.39.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-12955

Affected Products

Live Sales Notification For Woocommerce
Woocommerce