CVE-2025-12955: Live sales notification for WooCommerce <= 2.3.39 - Missing Authorization to Unauthenticated Customer Data Exposure
The Live sales notification for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.3.39. This is due to the "getOrders" function lacking proper authorization and capability checks when the plugin is configured to display recent order information. This makes it possible for unauthenticated attackers to extract sensitive customer information including buyer first names, city, state, country, purchase time and date, and product details.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12955?
CVE-2025-12955 is considered a high severity vulnerability due to the lack of proper authorization checks.
What versions are affected by CVE-2025-12955?
CVE-2025-12955 affects all versions of the Live sales notification for WooCommerce plugin up to and including 2.3.39.
How do I fix CVE-2025-12955?
To fix CVE-2025-12955, update the Live sales notification for WooCommerce plugin to version 2.3.40 or later.
What impact does CVE-2025-12955 have on my WooCommerce site?
CVE-2025-12955 could potentially allow unauthorized users to access order information on your WooCommerce site.
Where can I find more information about CVE-2025-12955?
Additional information about CVE-2025-12955 can typically be found in security advisories from the plugin vendor or cybersecurity databases.