{
 "id": "WPSEC-2026-0700",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0700/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0700/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0700/index.md",
 "title": "AI Powered Marketing <= 1.5.4 - Unauthenticated Insecure Direct Object Reference to Sensitive Information Exposure via Order Received Page",
 "description": "The AI Powered Marketing plugin for WordPress is vulnerable to Insecure Direct Object Reference via the WooCommerce order received page tracking script in all versions up to, and including, 1.5.4, due to the plugin building transaction data from the order ID in the URL without validating the order key or that a registered customer is the logged-in user. This makes it possible for unauthenticated attackers to enumerate order IDs and view other customers' order details, including purchased items, prices, totals, tax, currency, and billing city, state and country, in the page's tracking script output.",
 "plugin": {
  "slug": "kliken-marketing-for-google",
  "name": "AI Powered Marketing",
  "full_name": "AI Powered Marketing",
  "wordpress_org": "https://wordpress.org/plugins/kliken-marketing-for-google/",
  "advisories_url": "https://wpsec.com/vuln/plugin/kliken-marketing-for-google/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/kliken-marketing-for-google"
 },
 "type": "IDOR",
 "cwe": [
  "CWE-639"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.3,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "1.5.5",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 1.5.5"
  ]
 },
 "introduced_in": null,
 "fixed_in": "1.5.5",
 "remediation": "Update to 1.5.5 or later.",
 "fix_released": "2026-10-08T21:07:39+00:00",
 "published": "2026-10-10T15:41:27+00:00",
 "updated": "2026-10-10T14:53:13.821863+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0700/",
  "https://plugins.svn.wordpress.org/kliken-marketing-for-google/tags/1.5.5/",
  "https://wordpress.org/plugins/kliken-marketing-for-google/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/kliken-marketing-for-google",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-10"
 }
}