PT-2025-49345 · WordPress · Helloprint Plugin

Published

2025-12-06

·

Updated

2025-12-06

·

CVE-2025-13666

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Helloprint plugin for WordPress versions up to and including 2.1.2
Description The Helloprint plugin for WordPress is subject to a missing authorization issue. The plugin registers a public REST API endpoint without verifying request authenticity. This allows unauthenticated attackers to modify WooCommerce order statuses. The vulnerable API endpoint is '/wp-json/helloprint/v1/complete order from helloprint callback', and it can be exploited by providing a valid order reference ID.
Recommendations Update the Helloprint plugin to a version later than 2.1.2.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-13666

Affected Products

Helloprint Plugin