CyberRota Analysis
AI-GeneratedThe Order Sync with Zendesk for WooCommerce plugin for WordPress prior to version 2.2.3 is vulnerable due to a lack of capability checks on a REST API endpoint, enabling unauthenticated attackers to access sensitive order history and purchase totals of customers by knowing or enumerating their email addresses. This vulnerability poses a significant risk to customer privacy and data security. WordPress site administrators using this plugin should prioritize immediate updates to mitigate potential data exposure.
Original NVD Description
The Order Sync with Zendesk for WooCommerce WordPress plugin before 2.2.3 does not perform any capability check on one of its REST API endpoints, and does not verify that the requester owns the account being queried, allowing unauthenticated attackers to retrieve the order history and purchase totals of any customer whose email address they know or can enumerate.