PT-2026-20220 · WordPress+1 · Order Splitter For Woocommerce+1
Athiwat Tiprasaharn
·
Published
2026-02-18
·
Updated
2026-02-18
·
CVE-2025-12075
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Order Splitter for WooCommerce plugin for WordPress versions up to and including 5.3.5
Description
The Order Splitter for WooCommerce plugin for WordPress has a flaw that allows unauthorized access to data. This is due to a missing capability check on the
/wos troubleshooting API endpoint. Attackers with Subscriber-level access or higher can view information about orders belonging to other users.Recommendations
Update the Order Splitter for WooCommerce plugin to a version later than 5.3.5.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Order Splitter For Woocommerce
Woocommerce