Ads + Pixel for Meta <= 1.2.2 - Unauthenticated Insecure Direct Object Reference to Order Information Disclosure via 'order-received' Parameter

Medium 5.3 CWE-639Fixed in 1.2.3
ID
WPSEC-2026-0722
Plugin
Kliken: Ads + Pixel for Meta (kliken-ads-pixel-for-meta)
Affected
all versions before 1.2.3
Remediation
Update to 1.2.3 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness
CWE-639
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-10
Attack surface
Ads + Pixel for Meta on WPSec AttackSurface
Fix released
Published

Description

The Kliken: Ads + Pixel for Meta plugin for WordPress is vulnerable to Insecure Direct Object Reference via the 'order-received' query variable in all versions up to, and including, 1.2.2, due to the purchase tracking code loading the order named by that user-controlled value without validating the order key or checking that the order belongs to the current user. This makes it possible for unauthenticated attackers to go through order IDs on the WooCommerce order received endpoint and read other customers' order details from the tracking script on the page. These details include order totals, subtotal and tax, purchased products with their prices and quantities, and the billing city, state and country.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0