CyberRota Analysis
AI-GeneratedThe WP Helper Premium WordPress plugin versions prior to 4.7.6 are vulnerable due to inadequate verification of order keys, which allows unauthenticated users to access and manipulate other customers' order details and personal information. This vulnerability can be exploited when WooCommerce is active and the optional order confirmation page module is enabled. WordPress site administrators using this plugin should prioritize immediate updates to mitigate potential data exposure and unauthorized order modifications.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
The WP Helper Premium WordPress plugin before 4.7.6 does not verify the order key when rendering its custom order confirmation page or when handling the related AJAX actions, allowing unauthenticated users to view other customers' order details, including personal information, as well as change the state of arbitrary orders. Exploitation requires WooCommerce to be active and the WP Helper Premium WordPress plugin before 4.7.6's optional order confirmation page module to be enabled.