PT-2025-47835 · WordPress · Oneclick Chat To Order
Published
2025-11-22
·
Updated
2025-11-29
·
CVE-2025-13526
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
OneClick Chat to Order plugin for WordPress versions up to and including 1.0.8
Description
The OneClick Chat to Order plugin for WordPress is susceptible to an Insecure Direct Object Reference issue. This is due to a lack of validation on a user-controlled key within the
wa order thank you override function. An unauthenticated attacker can potentially view sensitive customer information, including names, email addresses, phone numbers, billing and shipping addresses, order contents, and payment methods, by modifying the order ID in the URL.Recommendations
Versions prior to 1.0.8 should be updated. As a temporary workaround, restrict access to the
wa order thank you override function until a patch is available.Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oneclick Chat To Order