PT-2025-48015 · Unknown+1 · Woocommerce+1
Published
2025-11-25
·
Updated
2025-11-25
·
CVE-2025-13452
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress versions up to and including 14
Description
The software is susceptible to a missing authorization issue. A flawed permission check in the REST API permission callback allows attackers to bypass authentication when no nonce is provided. This enables unauthenticated attackers to impersonate any WordPress user and inject arbitrary messages into any WooCommerce order conversation. Attackers can achieve this by directly calling the REST endpoint with controlled
user id, order id, and context parameters.Recommendations
Versions prior to and including 14 should be updated.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Orderconvo
Woocommerce