Information Exposure in WooCommerce Plugin by WordPress
CVE-2025-12545
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 18 November 2025
What is CVE-2025-12545?
The Pixel Manager for WooCommerce plugin, which enhances e-commerce tracking capabilities, is susceptible to an Information Exposure flaw. This vulnerability arises from the ajax_pmw_get_product_ids() function, lacking sufficient restrictions, which allows unauthorized users to access sensitive data from password-protected, private, or draft products. This exploitation potential poses a significant risk to merchants who rely on this plugin for analytics and marketing integration.
Affected Version(s)
Pixel Manager for WooCommerce β Track Con and Analytics, Google Ads, TikTok and more * <= 1.49.2