# AI Powered Marketing <= 1.5.4 - Unauthenticated Insecure Direct Object Reference to Sensitive Information Exposure via Order Received Page

- **ID:** WPSEC-2026-0700
- **Plugin:** AI Powered Marketing (`kliken-marketing-for-google`), https://wordpress.org/plugins/kliken-marketing-for-google/
- **Affected versions:** all versions before 1.5.5
- **Fixed in:** 1.5.5 (Update to 1.5.5 or later.)
- **Severity:** Medium 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
- **Weakness:** CWE-639
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-10)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/kliken-marketing-for-google
- **Fix released:** 2026-10-08
- **Published:** 2026-10-10
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0700/

## Description

The AI Powered Marketing plugin for WordPress is vulnerable to Insecure Direct Object Reference via the WooCommerce order received page tracking script in all versions up to, and including, 1.5.4, due to the plugin building transaction data from the order ID in the URL without validating the order key or that a registered customer is the logged-in user. This makes it possible for unauthenticated attackers to enumerate order IDs and view other customers' order details, including purchased items, prices, totals, tax, currency, and billing city, state and country, in the page's tracking script output.

## References

- https://wpsec.com/vuln/WPSEC-2026-0700/
- https://plugins.svn.wordpress.org/kliken-marketing-for-google/tags/1.5.5/
- https://wordpress.org/plugins/kliken-marketing-for-google/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0700/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
