Information Exposure in WooCommerce Plugin by WordPress
CVE-2025-12545

5.3MEDIUM

What is CVE-2025-12545?

The Pixel Manager for WooCommerce plugin, which enhances e-commerce tracking capabilities, is susceptible to an Information Exposure flaw. This vulnerability arises from the ajax_pmw_get_product_ids() function, lacking sufficient restrictions, which allows unauthorized users to access sensitive data from password-protected, private, or draft products. This exploitation potential poses a significant risk to merchants who rely on this plugin for analytics and marketing integration.

Affected Version(s)

Pixel Manager for WooCommerce – Track Con and Analytics, Google Ads, TikTok and more * <= 1.49.2

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Athiwat Tiprasaharn
.
CVE-2025-12545 : Information Exposure in WooCommerce Plugin by WordPress