Sensitive Information Disclosure in WooCommerce PayPal Payments Plugin by WordPress
CVE-2025-14073

5.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
1 August 2026

What is CVE-2025-14073?

The WooCommerce PayPal Payments plugin for WordPress is susceptible to a Sensitive Information Disclosure vulnerability caused by an Insecure Direct Object Reference. This occurs in all versions up to and including 3.3.2, which allows unauthenticated attackers to exploit the enqueue_paypal_insights_script_on_order_received() function. Due to inadequate validation of a user-controlled key, attackers can potentially retrieve sensitive order information, such as order keys. This information may be exploited to gain access to complete customer billing details, including name, email, phone number, and address, through the WooCommerce Store API within a 10-minute window after an order is created.

Affected Version(s)

WooCommerce PayPal Payments 0 <= 3.3.2

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Drew Webber (mcdruid)
.