CVE-2025-48331: WordPress WooCommerce Orders & Customers Exporter <= 5.0 - Sensitive Data Exposure Vulnerability
Insertion of Sensitive Information Into Sent Data vulnerability in Vanquish WooCommerce Orders & Customers Exporter allows Retrieve Embedded Sensitive Data.This issue affects WooCommerce Orders & Customers Exporter: from n/a through 5.0.
Other sources
Insertion of Sensitive Information Into Sent Data vulnerability in vanquish WooCommerce Orders & Customers Exporter woocommerce-orders-customers-exporter allows Retrieve Embedded Sensitive Data.This issue affects WooCommerce Orders & Customers Exporter: from n/a through <= 5.0.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48331?
CVE-2025-48331 is classified as a critical vulnerability due to its potential for exposing sensitive information.
How do I fix CVE-2025-48331?
To fix CVE-2025-48331, update the Vanquish WooCommerce Orders & Customers Exporter plugin to version 5.1 or later.
What kind of data is affected by CVE-2025-48331?
CVE-2025-48331 affects the retrieval of embedded sensitive data within exported WooCommerce orders and customer information.
Who is affected by CVE-2025-48331?
Any user of the Vanquish WooCommerce Orders & Customers Exporter plugin version 5.0 or earlier is affected by CVE-2025-48331.
Is CVE-2025-48331 being actively exploited?
As of now, there are no reports indicating that CVE-2025-48331 is being actively exploited in the wild.