{
 "id": "WPSEC-2026-0722",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0722/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0722/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0722/index.md",
 "title": "Ads + Pixel for Meta <= 1.2.2 - Unauthenticated Insecure Direct Object Reference to Order Information Disclosure via 'order-received' Parameter",
 "description": "The Kliken: Ads + Pixel for Meta plugin for WordPress is vulnerable to Insecure Direct Object Reference via the 'order-received' query variable in all versions up to, and including, 1.2.2, due to the purchase tracking code loading the order named by that user-controlled value without validating the order key or checking that the order belongs to the current user. This makes it possible for unauthenticated attackers to go through order IDs on the WooCommerce order received endpoint and read other customers' order details from the tracking script on the page. These details include order totals, subtotal and tax, purchased products with their prices and quantities, and the billing city, state and country.",
 "plugin": {
  "slug": "kliken-ads-pixel-for-meta",
  "name": "Ads + Pixel for Meta",
  "full_name": "Kliken: Ads + Pixel for Meta",
  "wordpress_org": "https://wordpress.org/plugins/kliken-ads-pixel-for-meta/",
  "advisories_url": "https://wpsec.com/vuln/plugin/kliken-ads-pixel-for-meta/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/kliken-ads-pixel-for-meta"
 },
 "type": "IDOR",
 "cwe": [
  "CWE-639"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 5.3,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "1.2.3",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 1.2.3"
  ]
 },
 "introduced_in": null,
 "fixed_in": "1.2.3",
 "remediation": "Update to 1.2.3 or later.",
 "fix_released": "2026-10-08T21:06:23+00:00",
 "published": "2026-10-10T15:41:27+00:00",
 "updated": "2026-10-10T14:53:36.458802+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0722/",
  "https://plugins.svn.wordpress.org/kliken-ads-pixel-for-meta/tags/1.2.3/",
  "https://wordpress.org/plugins/kliken-ads-pixel-for-meta/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/kliken-ads-pixel-for-meta",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-10"
 }
}