CVE-2025-12545
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-12545 is an information exposure vulnerability in the Pixel Manager for WooCommerce WordPress plugin (versions up to and including 1.49.2) that allows unauthenticated attackers to extract data from password-protected, private, or draft WooCommerce products. The flaw was published on November 18, 2025, and assigned a CVSS v3.1 base score of 5.3 (Medium). It was discovered and reported by Wordfence (Wordfence, Red Hat CVE).

Technical details

The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). The vulnerable code resides in the ajax_pmw_get_product_ids() function within includes/pixels/class-pixel-manager.php (lines 343 and 1235 in version 1.49.2), which handles AJAX requests but fails to enforce proper access controls on which products can be queried. Because the function does not restrict results based on product visibility or authentication status, any unauthenticated HTTP request can enumerate product IDs and associated data for products that should be restricted (Wordfence, WordPress Trac).

Impact

Successful exploitation allows unauthenticated remote attackers to read product data — including titles, IDs, and potentially pricing or inventory details — from WooCommerce products that store owners have intentionally restricted via password protection, draft status, or private visibility. This primarily affects confidentiality with no impact on integrity or availability. While the scope is limited to product metadata rather than full system compromise, exposure of unreleased or confidential product listings could harm business operations or reveal competitive information (Wordfence, ENISA EUVD).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2025-12545. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.027%, indicating a very low probability of exploitation in the near term. The attack requires no authentication, no user interaction, and low complexity, making it trivially exploitable if targeted, but the limited data exposure reduces attacker incentive (Wordfence, Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Pixel Manager for WooCommerce plugin (version ≤ 1.49.2) using tools like WPScan, Shodan, or by checking the plugin's readme.txt at wp-content/plugins/woocommerce-google-adwords-conversion-tracking-tag/readme.txt.
  2. Craft AJAX request: Send an unauthenticated HTTP POST or GET request to the WordPress AJAX endpoint (/wp-admin/admin-ajax.php) with the action parameter targeting the vulnerable function (e.g., action=pmw_get_product_ids).
  3. Extract product data: Parse the JSON response, which will include product IDs and associated metadata for password-protected, private, or draft products that should not be publicly accessible.
  4. Enumerate further: Use the returned product IDs to make additional requests or correlate with other WordPress endpoints to gather further product details (Wordfence, WordPress Trac).

Indicators of compromise

  • Network: Unusual unauthenticated POST or GET requests to /wp-admin/admin-ajax.php with parameters referencing pmw_get_product_ids or similar Pixel Manager AJAX actions from unexpected IP addresses.
  • Logs: WordPress or web server access logs showing repeated requests to admin-ajax.php without a valid session cookie, particularly from automated/scripted user agents.
  • Logs: High-frequency AJAX requests to the plugin's endpoint in a short time window, suggesting automated enumeration.

Mitigation and workarounds

Update the Pixel Manager for WooCommerce plugin to version 1.49.3 or later, which contains the fix for this vulnerability. No configuration-based workaround is documented; upgrading is the only recommended remediation. Site administrators should audit their WordPress plugin inventory and apply updates promptly, particularly for plugins handling sensitive product data (Wordfence, ENISA EUVD).

Community reactions

Sucuri included CVE-2025-12545 in their November 2025 vulnerability patch roundup, recommending WordPress site owners update affected plugins promptly (Sucuri Blog). No significant broader media coverage or notable researcher commentary beyond standard vulnerability disclosure channels has been identified.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-13784CRITICAL9.8
  • arforms-form-builder
NoYesAug 16, 2026
CVE-2026-65640HIGH8.8
  • wordpress
NoYesAug 17, 2026
CVE-2026-11801HIGH7.5
  • wpadverts
NoYesAug 18, 2026
CVE-2026-13700MEDIUM5.9
  • wooms
NoNoAug 17, 2026
CVE-2026-14832MEDIUM5.3
  • shopsmart-loyalty-for-woocommerce
NoNoAug 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management