# Ads + Pixel for Meta <= 1.2.2 - Unauthenticated Insecure Direct Object Reference to Order Information Disclosure via 'order-received' Parameter

- **ID:** WPSEC-2026-0722
- **Plugin:** Kliken: Ads + Pixel for Meta (`kliken-ads-pixel-for-meta`), https://wordpress.org/plugins/kliken-ads-pixel-for-meta/
- **Affected versions:** all versions before 1.2.3
- **Fixed in:** 1.2.3 (Update to 1.2.3 or later.)
- **Severity:** Medium 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
- **Weakness:** CWE-639
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-10)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/kliken-ads-pixel-for-meta
- **Fix released:** 2026-10-08
- **Published:** 2026-10-10
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0722/

## Description

The Kliken: Ads + Pixel for Meta plugin for WordPress is vulnerable to Insecure Direct Object Reference via the 'order-received' query variable in all versions up to, and including, 1.2.2, due to the purchase tracking code loading the order named by that user-controlled value without validating the order key or checking that the order belongs to the current user. This makes it possible for unauthenticated attackers to go through order IDs on the WooCommerce order received endpoint and read other customers' order details from the tracking script on the page. These details include order totals, subtotal and tax, purchased products with their prices and quantities, and the billing city, state and country.

## References

- https://wpsec.com/vuln/WPSEC-2026-0722/
- https://plugins.svn.wordpress.org/kliken-ads-pixel-for-meta/tags/1.2.3/
- https://wordpress.org/plugins/kliken-ads-pixel-for-meta/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0722/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
