PT-2025-52678 · Automattic · Woocommerce

Peter Stöckli

·

Published

2025-12-22

·

Updated

2025-12-22

·

CVE-2025-15033

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions WooCommerce versions 8.1 through 10.4.2
Description A flaw exists in WooCommerce that could allow authenticated customers to view order information belonging to guest customers, specifically on sites with a particular setup.
Recommendations Update to WooCommerce version 10.4.3 or later. Update to WooCommerce version 8.1.3 or later.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-15033

Affected Products

Woocommerce