Description

The Live sales notification for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.3.39. This is due to the "getOrders" function lacking proper authorization and capability checks when the plugin is configured to display recent order information. This makes it possible for unauthenticated attackers to extract sensitive customer information including buyer first names, city, state, country, purchase time and date, and product details.

INFO

Published Date :

2025-11-18T09:27:36.608Z

Last Modified :

2026-04-08T16:40:30.736Z

Source :

Wordfence
AFFECTED PRODUCTS

The following products are affected by CVE-2025-12955 vulnerability.

Vendors Products
Rajeshsingh520
  • Live Sales Notification For Woocommerce
Woocommerce
  • Woocommerce
Wordpress
  • Wordpress

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact