CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 6.5. See the original NVD description below for full technical details.
CVE
CVE-2025-15033
Severity
MEDIUM
CVSS
6.5
EPSS
0.30%
Original NVD Description
A vulnerability in WooCommerce 8.1 to 10.4.2 can allow logged-in customers to access order data of guest customers on sites with a certain configuration. This has been fixed in WooCommerce 10.4.3, as well as all the previously affected versions through point releases, starting from 8.1, where it has been fixed in 8.1.3. It does not affect WooCommerce 8.0 or earlier.