PT-2025-48011 · WordPress · Orderconvo

Published

2025-11-25

·

Updated

2025-11-25

·

CVE-2025-13389

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OrderConvo plugin for WordPress versions up to and including 14
Description The OrderConvo plugin for WordPress is susceptible to unauthorized data access. A missing capability check within the get order by id() function allows unauthenticated attackers to view sensitive WooCommerce order details and private conversation messages between customers and store administrators. Attackers can achieve this by providing an arbitrary order ID.
Recommendations Update the OrderConvo plugin to a version newer than 14.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-13389

Affected Products

Orderconvo