AI Powered Marketing <= 1.5.4 - Unauthenticated Insecure Direct Object Reference to Sensitive Information Exposure via Order Received Page

Medium 5.3 CWE-639Fixed in 1.5.5
ID
WPSEC-2026-0700
Plugin
AI Powered Marketing (kliken-marketing-for-google)
Affected
all versions before 1.5.5
Remediation
Update to 1.5.5 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness
CWE-639
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-10
Attack surface
AI Powered Marketing on WPSec AttackSurface
Fix released
Published

Description

The AI Powered Marketing plugin for WordPress is vulnerable to Insecure Direct Object Reference via the WooCommerce order received page tracking script in all versions up to, and including, 1.5.4, due to the plugin building transaction data from the order ID in the URL without validating the order key or that a registered customer is the logged-in user. This makes it possible for unauthenticated attackers to enumerate order IDs and view other customers' order details, including purchased items, prices, totals, tax, currency, and billing city, state and country, in the page's tracking script output.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0