
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-12545 is an information exposure vulnerability in the Pixel Manager for WooCommerce WordPress plugin (versions up to and including 1.49.2) that allows unauthenticated attackers to extract data from password-protected, private, or draft WooCommerce products. The flaw was published on November 18, 2025, and assigned a CVSS v3.1 base score of 5.3 (Medium). It was discovered and reported by Wordfence (Wordfence, Red Hat CVE).
The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). The vulnerable code resides in the ajax_pmw_get_product_ids() function within includes/pixels/class-pixel-manager.php (lines 343 and 1235 in version 1.49.2), which handles AJAX requests but fails to enforce proper access controls on which products can be queried. Because the function does not restrict results based on product visibility or authentication status, any unauthenticated HTTP request can enumerate product IDs and associated data for products that should be restricted (Wordfence, WordPress Trac).
Successful exploitation allows unauthenticated remote attackers to read product data — including titles, IDs, and potentially pricing or inventory details — from WooCommerce products that store owners have intentionally restricted via password protection, draft status, or private visibility. This primarily affects confidentiality with no impact on integrity or availability. While the scope is limited to product metadata rather than full system compromise, exposure of unreleased or confidential product listings could harm business operations or reveal competitive information (Wordfence, ENISA EUVD).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2025-12545. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.027%, indicating a very low probability of exploitation in the near term. The attack requires no authentication, no user interaction, and low complexity, making it trivially exploitable if targeted, but the limited data exposure reduces attacker incentive (Wordfence, Red Hat CVE).
wp-content/plugins/woocommerce-google-adwords-conversion-tracking-tag/readme.txt./wp-admin/admin-ajax.php) with the action parameter targeting the vulnerable function (e.g., action=pmw_get_product_ids)./wp-admin/admin-ajax.php with parameters referencing pmw_get_product_ids or similar Pixel Manager AJAX actions from unexpected IP addresses.admin-ajax.php without a valid session cookie, particularly from automated/scripted user agents.Update the Pixel Manager for WooCommerce plugin to version 1.49.3 or later, which contains the fix for this vulnerability. No configuration-based workaround is documented; upgrading is the only recommended remediation. Site administrators should audit their WordPress plugin inventory and apply updates promptly, particularly for plugins handling sensitive product data (Wordfence, ENISA EUVD).
Sucuri included CVE-2025-12545 in their November 2025 vulnerability patch roundup, recommending WordPress site owners update affected plugins promptly (Sucuri Blog). No significant broader media coverage or notable researcher commentary beyond standard vulnerability disclosure channels has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."