WordPress Plugin Vulnerabilities

WooCommerce - Subscriber/Customer+ Order Data Disclosure

Description

A vulnerability in WooCommerce 8.1 to 10.4.2 can allow logged-in customers to access order data of guest customers on sites with a certain configuration.

This has been fixed in WooCommerce 10.4.3, as well as all the previously affected versions through point releases, starting from 8.1, where it has been fixed in 8.1.3.

It does not affect WooCommerce 8.0 or earlier.

Proof of Concept

Affects Plugins

Fixed in 10.4.3
Fixed in 10.3.7
Fixed in 10.2.3
Fixed in 10.1.3
Fixed in 10.0.5
Fixed in 9.9.6
Fixed in 9.8.6
Fixed in 9.7.2
Fixed in 9.6.3
Fixed in 9.5.3
Fixed in 9.4.4
Fixed in 9.3.5
Fixed in 9.2.4
Fixed in 9.1.5
Fixed in 9.0.3
Fixed in 8.9.4
Fixed in 8.8.6
Fixed in 8.7.2
Fixed in 8.6.3
Fixed in 8.5.4
Fixed in 8.4.2
Fixed in 8.3.3
Fixed in 8.2.4
Fixed in 8.1.3

References

Classification

Type
SENSITIVE DATA DISCLOSURE
CWE

Miscellaneous

Original Researcher
Peter Stöckli
Submitter website
Verified
Yes

Timeline

Publicly Published
2025-12-22 (about 22 hours ago)
Added
2025-12-22 (about 5 hours ago)
Last Updated
2025-12-22 (about 5 hours ago)

Other