CVE-2025-15033
Last modified
CVE-2025-15033 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A vulnerability in WooCommerce 8.1 to 10.4.2 can allow logged-in customers to access order data of guest customers on sites with a certain configuration. This has been fixed in WooCommerce 10.4.3, as well as all the previously affected versions through point releases, starting from 8.1, where it has been fixed in 8.1.3. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
A vulnerability in WooCommerce 8.1 to 10.4.2 can allow logged-in customers to access order data of guest customers on sites with a certain configuration. This has been fixed in WooCommerce 10.4.3, as well as all the previously affected versions through point releases, starting from 8.1, where it has been fixed in 8.1.3. It does not affect WooCommerce 8.0 or earlier.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-15033?
How severe is CVE-2025-15033?
How do I fix CVE-2025-15033?
Are you affected by CVE-2025-15033?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
