CVE-2025-13526
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-13526 is an Insecure Direct Object Reference (IDOR) vulnerability in the OneClick Chat to Order WordPress plugin (also known as "oneclick-whatsapp-order") that allows unauthenticated attackers to access sensitive customer order data by manipulating order IDs in URLs. All versions up to and including 1.0.8 are affected. The vulnerability was published on November 22, 2025, with a fix available in version 1.0.9. It carries a CVSS v3.1 base score of 7.5 (High) (Wordfence, Red Hat CVE).

Technical details

The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). The vulnerability exists in the wa_order_thank_you_override function within includes/buttons/wa-order-thank-you.php, which processes a user-controlled order ID parameter from the URL without performing any authorization or ownership validation. An unauthenticated attacker can simply increment or enumerate the order ID value in the URL to retrieve order details belonging to other customers. No authentication, session token, or special privileges are required to exploit this flaw (Wordfence, WordPress Trac).

Impact

Successful exploitation exposes sensitive customer PII and transactional data, including full names, email addresses, phone numbers, billing and shipping addresses, order contents, and payment methods. Because no authentication is required and order IDs are typically sequential integers, an attacker can enumerate all orders on a vulnerable WooCommerce store, resulting in a full data breach of the store's customer base. The impact is limited to confidentiality — there is no integrity or availability impact — but the breadth of exposed data makes this a significant privacy and compliance risk (Wordfence, Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the OneClick Chat to Order plugin (version ≤ 1.0.8) by searching for plugin-specific indicators (e.g., wp-content/plugins/oneclick-whatsapp-order/) using tools like Google dorks, Shodan, or WPScan.
  2. Locate the thank-you page: Place a test order on the target WooCommerce store to observe the structure of the order confirmation (thank-you) URL, which typically includes an order_id or similar parameter.
  3. Enumerate order IDs: Modify the order ID parameter in the URL (e.g., changing ?order_id=1001 to ?order_id=1000, 999, etc.) to access other customers' order confirmation pages via the vulnerable wa_order_thank_you_override function.
  4. Harvest customer data: For each valid order ID, the response reveals the customer's name, email address, phone number, billing/shipping address, order contents, and payment method — all without any authentication (Wordfence, WordPress Trac).

Indicators of compromise

  • Network: Repeated HTTP GET requests to WooCommerce order thank-you or confirmation URLs with sequentially incrementing or rapidly changing order ID parameters from a single IP address or user agent.
  • Logs: Web server access logs showing high-frequency requests to paths matching /checkout/order-received/ or similar WooCommerce thank-you endpoints with varied order IDs and no associated authenticated session cookies.
  • Logs: Requests originating from automated tools (e.g., unusual User-Agent strings, high request rates) targeting the wa_order_thank_you_override endpoint.

Mitigation and workarounds

Update the OneClick Chat to Order plugin to version 1.0.9 or later, which includes the fix for this vulnerability (WordPress Trac Changeset). No configuration-based workaround is available; the only effective remediation is applying the patch. Site administrators should also audit web server access logs for signs of prior enumeration activity and consider notifying affected customers if exploitation is suspected.

Community reactions

The vulnerability was reported by Wordfence and received standard coverage from security aggregators and social media accounts focused on CVE tracking. RedPacketSecurity posted an alert on social media, and the CVE was noted on Bluesky and Mastodon by automated CVE-tracking accounts. A Medium article titled "CVE-2025-13526: 7 Lessons from the OneClick Chat to Order IDOR" was published, offering community analysis of the vulnerability's implications (RedPacket Security).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-14270HIGH8.8
  • woocommerce-tm-extra-checkout-options-addon
NoYesJul 29, 2026
CVE-2026-5060MEDIUM6.5
  • masterstudy-lms-learning-management-system
NoYesJul 29, 2026
CVE-2026-8791MEDIUM6.4
  • booking-system-trafft
NoYesJul 29, 2026
CVE-2026-7436MEDIUM6.4
  • wpc-badge-management
NoYesJul 29, 2026
CVE-2026-6089MEDIUM4.9
  • easy-sticky-sidebar
NoYesJul 29, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management