PT-2026-20613 · WordPress · Oneclick Chat To Order
Published
2026-02-19
·
Updated
2026-02-19
·
CVE-2025-14270
CVSS v3.1
2.7
Low
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
The OneClick Chat to Order plugin for WordPress versions up to and including 1.0.9
Description
The plugin does not properly verify user authorization when performing actions within the
wa order number save number field function. This allows authenticated attackers with Editor-level access or higher to modify WhatsApp phone numbers used by the plugin. Successful exploitation can redirect customer orders and messages to phone numbers controlled by the attacker.Recommendations
Update the plugin to a version newer than 1.0.9.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oneclick Chat To Order