PT-2025-48015 · Unknown+1 · Woocommerce+1

Published

2025-11-25

·

Updated

2025-11-25

·

CVE-2025-13452

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress versions up to and including 14
Description The software is susceptible to a missing authorization issue. A flawed permission check in the REST API permission callback allows attackers to bypass authentication when no nonce is provided. This enables unauthenticated attackers to impersonate any WordPress user and inject arbitrary messages into any WooCommerce order conversation. Attackers can achieve this by directly calling the REST endpoint with controlled user id, order id, and context parameters.
Recommendations Versions prior to and including 14 should be updated.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2025-13452

Affected Products

Orderconvo
Woocommerce