CVE-2025-14270: OneClick Chat to Order <= 1.0.9 - Missing Authorization to Authenticated (Editor+) Plugin Settings Update
The OneClick Chat to Order plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.0.9. This is due to the plugin not properly verifying that a user is authorized to perform an action in the waordernumbersavenumberfield function. This makes it possible for authenticated attackers, with Editor-level access and above, to modify WhatsApp phone numbers used by the plugin, redirecting customer orders and messages to attacker-controlled phone numbers.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14270?
CVE-2025-14270 has a medium severity due to the potential for unauthorized access to plugin settings.
How do I fix CVE-2025-14270?
To fix CVE-2025-14270, update the OneClick Chat to Order plugin to version 1.1.0 or later.
What versions of the OneClick Chat to Order plugin are affected by CVE-2025-14270?
CVE-2025-14270 affects all versions of the OneClick Chat to Order plugin up to and including 1.0.9.
What type of vulnerability is CVE-2025-14270?
CVE-2025-14270 is an authorization bypass vulnerability that allows unauthorized settings updates.
Who is affected by CVE-2025-14270?
Users of the OneClick Chat to Order plugin on WordPress running version 1.0.9 or earlier are affected by CVE-2025-14270.