Insecure Direct Object Reference in WooCommerce Automatic Order Printing Plugin
CVE-2025-1284
4.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 24 April 2025
What is CVE-2025-1284?
The WooCommerce Automatic Order Printing plugin, previously known as WooCommerce Google Cloud Print, is affected by a vulnerability that allows authenticated users with Subscriber-level access or higher to exploit an Insecure Direct Object Reference. This flaw exists in all versions up to and including 4.1, specifically within the xc_woo_printer_preview AJAX action. Due to inadequate validation of a user-controlled key, this vulnerability can result in unauthorized access to view invoices and orders belonging to other users, potentially exposing sensitive information.
Affected Version(s)
Woocommerce Automatic Order Printing | ( Formerly WooCommerce Google Cloud Print) * <= 4.1