AI Powered Marketing <= 1.5.4 - Unauthenticated Insecure Direct Object Reference to Sensitive Information Exposure via Order Received Page
- ID
- WPSEC-2026-0700
- Plugin
- AI Powered Marketing (kliken-marketing-for-google)
- Affected
- all versions before 1.5.5
- Remediation
- Update to 1.5.5 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Weakness
- CWE-639
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-10
- Attack surface
- AI Powered Marketing on WPSec AttackSurface
- Fix released
- Published
Description
The AI Powered Marketing plugin for WordPress is vulnerable to Insecure Direct Object Reference via the WooCommerce order received page tracking script in all versions up to, and including, 1.5.4, due to the plugin building transaction data from the order ID in the URL without validating the order key or that a registered customer is the logged-in user. This makes it possible for unauthenticated attackers to enumerate order IDs and view other customers' order details, including purchased items, prices, totals, tax, currency, and billing city, state and country, in the page's tracking script output.
References
- https://wpsec.com/vuln/WPSEC-2026-0700/
- https://plugins.svn.wordpress.org/kliken-marketing-for-google/tags/1.5.5/
- https://wordpress.org/plugins/kliken-marketing-for-google/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS