The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 14. This is due to a flawed permission check in the REST API permission callback that returns true when no nonce is provided. This makes it possible for unauthenticated attackers to impersonate any WordPress user and inject arbitrary messages into any WooCommerce order conversation by directly calling the REST endpoint with controlled user_id, order_id, and context parameters.
Metrics
Affected Vendors & Products
References
History
Wed, 26 Nov 2025 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Najeebmedia
Najeebmedia admin And Customer Messages After Order For Woocommerce Woocommerce Woocommerce woocommerce Wordpress Wordpress wordpress |
|
| Vendors & Products |
Najeebmedia
Najeebmedia admin And Customer Messages After Order For Woocommerce Woocommerce Woocommerce woocommerce Wordpress Wordpress wordpress |
Tue, 25 Nov 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Nov 2025 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 14. This is due to a flawed permission check in the REST API permission callback that returns true when no nonce is provided. This makes it possible for unauthenticated attackers to impersonate any WordPress user and inject arbitrary messages into any WooCommerce order conversation by directly calling the REST endpoint with controlled user_id, order_id, and context parameters. | |
| Title | Admin and Customer Messages After Order for WooCommerce: OrderConvo <= 14 - Missing Authorization to Unauthenticated User Impersonation in Order Messages | |
| Weaknesses | CWE-639 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2025-11-25T07:28:20.236Z
Updated: 2025-11-25T15:43:16.139Z
Reserved: 2025-11-19T19:28:16.353Z
Link: CVE-2025-13452
Updated: 2025-11-25T15:43:12.168Z
Status : Awaiting Analysis
Published: 2025-11-25T08:15:51.740
Modified: 2025-11-25T22:16:16.690
Link: CVE-2025-13452
No data.