CVE-2025-1284 Details
Description
The Woocommerce Automatic Order Printing | ( Formerly WooCommerce Google Cloud Print) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1 via the xc_woo_printer_preview AJAX action due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view other user's invoices and orders which can contain sensitive information.
A vulnerability allowing Insecure Direct Object Reference (IDOR) has been identified in the Woocommerce Automatic Order Printing plugin for WordPress, in all versions through 4.1. The issue arises in the xc_woo_printer_preview AJAX action, where a user-controlled key lacks proper validation. This vulnerability enables authenticated attackers with Subscriber-level access and above to access and view invoices and orders belonging to other users, potentially exposing sensitive information.
No known patch is available. Users are advised to review the vulnerability details and consider uninstalling the affected plugin.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 24, 2025CISA-ADP
Assessed Apr 24, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://codecanyon.net/item/woocommerce-google-cloud-print/21129093 | [email protected] | Broken LinkProductVendor |
| https://www.wordfence.com/threat-intel/vulnerabilities/id/6f593dce-4b56-46c0-becd-75fd16f165a8?source=cve | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Woocommerce Automatic Order Printing | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 24, 2025 | New CVE Received | [email protected] |
Volerion