CVE-2025-12075
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-12075 is a Missing Authorization vulnerability in the Order Splitter for WooCommerce plugin for WordPress that allows authenticated attackers to access other users' order data without proper authorization. The flaw affects all versions of the plugin up to and including 5.3.5. It was published on February 18, 2026, and carries a CVSS v3.1 base score of 4.3 (Medium) (Red Hat CVE).

Technical details

The root cause is a missing capability check (CWE-862) on the wos_troubleshooting AJAX endpoint exposed by the plugin. Because no authorization check is enforced on this endpoint, any authenticated WordPress user — including those with only Subscriber-level access — can invoke it and retrieve order information belonging to other users. The attack vector is network-based, requires low privileges, no user interaction, and low attack complexity (Red Hat CVE).

Impact

Successful exploitation results in unauthorized disclosure of other customers' order data, including potentially sensitive personal and transactional information stored in WooCommerce orders. The impact is limited to confidentiality (no integrity or availability impact), but on e-commerce sites this could expose customer names, addresses, purchase histories, and order details to any registered user (Red Hat CVE).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2025-12075. The EPSS score is very low at approximately 0.03%, indicating a low probability of near-term exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires at minimum a valid Subscriber-level WordPress account on the target site (Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Order Splitter for WooCommerce plugin (version ≤ 5.3.5) by inspecting plugin directories, readme files, or using tools like WPScan.
  2. Account Registration: Register or obtain a low-privilege WordPress account (Subscriber level or above) on the target site.
  3. Identify the AJAX endpoint: Locate the wos_troubleshooting AJAX action, typically accessible via wp-admin/admin-ajax.php?action=wos_troubleshooting.
  4. Send unauthorized request: Craft and send an authenticated HTTP POST or GET request to the AJAX endpoint, including the WordPress authentication cookies or nonce, to invoke the troubleshooting functionality.
  5. Retrieve order data: Parse the response to extract order information belonging to other users, which is returned without any authorization enforcement (Red Hat CVE).

Indicators of compromise

  • Network: Repeated authenticated requests to wp-admin/admin-ajax.php?action=wos_troubleshooting from low-privilege user accounts or from accounts that would not normally access order management functions.
  • Logs: WordPress access logs showing Subscriber-level users invoking the wos_troubleshooting AJAX action, especially in high frequency or across multiple order IDs.
  • Logs: Unusual access patterns where a single user account queries order data for many different order IDs in a short time window.

Mitigation and workarounds

Site administrators should update the Order Splitter for WooCommerce plugin to a version above 5.3.5 that includes a proper capability check on the wos_troubleshooting AJAX endpoint. Until a patched version is available or applied, consider deactivating the plugin or restricting AJAX endpoint access via a web application firewall (WAF) rule blocking unauthenticated or low-privilege access to admin-ajax.php?action=wos_troubleshooting. Limiting user registration on the WordPress site reduces the attack surface by preventing untrusted users from obtaining Subscriber-level accounts (Red Hat CVE).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77115HIGH7.1
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-77116MEDIUM4.3
  • brave-popup-builder
NoYesAug 23, 2026
CVE-2026-14853MEDIUM4.3
  • woocommerce-bookings
NoYesAug 23, 2026
CVE-2026-77003LOW2.7
  • content-mask
NoYesAug 23, 2026
CVE-2026-13598NONEN/A
  • restrictmate
NoYesAug 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management