Insecure Direct Object Reference in WooCommerce Automatic Order Printing Plugin
CVE-2025-1284

4.3MEDIUM

What is CVE-2025-1284?

The WooCommerce Automatic Order Printing plugin, previously known as WooCommerce Google Cloud Print, is affected by a vulnerability that allows authenticated users with Subscriber-level access or higher to exploit an Insecure Direct Object Reference. This flaw exists in all versions up to and including 4.1, specifically within the xc_woo_printer_preview AJAX action. Due to inadequate validation of a user-controlled key, this vulnerability can result in unauthorized access to view invoices and orders belonging to other users, potentially exposing sensitive information.

Affected Version(s)

Woocommerce Automatic Order Printing | ( Formerly WooCommerce Google Cloud Print) * <= 4.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lucio Sá
.
CVE-2025-1284 : Insecure Direct Object Reference in WooCommerce Automatic Order Printing Plugin