PT-2026-47141 · Unknown · Klamra Paycal For Aspaclaria
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Klamra Paycal for Aspaclaria versions prior to 1.1.5
Description
The plugin is subject to Insecure Direct Object Reference, a condition where an application provides direct access to objects based on user-supplied input. Authenticated attackers with subscriber-level access or higher can download arbitrary customer invoices by enumerating sequential post IDs through the
invoice id parameter. This occurs due to missing validation on a user-controlled key, leading to the exposure of sensitive billing personally identifiable information (PII), such as full names, email addresses, phone numbers, order totals, line items, and customer notes.Recommendations
Update the plugin to a version later than 1.1.4.
As a temporary workaround, restrict access to the
invoice id parameter to prevent unauthorized invoice downloads.Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Klamra Paycal For Aspaclaria