Sensitive Information Disclosure in WooCommerce PayPal Payments Plugin by WordPress
CVE-2025-14073
5.3MEDIUM
What is CVE-2025-14073?
The WooCommerce PayPal Payments plugin for WordPress is susceptible to a Sensitive Information Disclosure vulnerability caused by an Insecure Direct Object Reference. This occurs in all versions up to and including 3.3.2, which allows unauthenticated attackers to exploit the enqueue_paypal_insights_script_on_order_received() function. Due to inadequate validation of a user-controlled key, attackers can potentially retrieve sensitive order information, such as order keys. This information may be exploited to gain access to complete customer billing details, including name, email, phone number, and address, through the WooCommerce Store API within a 10-minute window after an order is created.
Affected Version(s)
WooCommerce PayPal Payments 0 <= 3.3.2