
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13526 is an Insecure Direct Object Reference (IDOR) vulnerability in the OneClick Chat to Order WordPress plugin (also known as "oneclick-whatsapp-order") that allows unauthenticated attackers to access sensitive customer order data by manipulating order IDs in URLs. All versions up to and including 1.0.8 are affected. The vulnerability was published on November 22, 2025, with a fix available in version 1.0.9. It carries a CVSS v3.1 base score of 7.5 (High) (Wordfence, Red Hat CVE).
The root cause is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). The vulnerability exists in the wa_order_thank_you_override function within includes/buttons/wa-order-thank-you.php, which processes a user-controlled order ID parameter from the URL without performing any authorization or ownership validation. An unauthenticated attacker can simply increment or enumerate the order ID value in the URL to retrieve order details belonging to other customers. No authentication, session token, or special privileges are required to exploit this flaw (Wordfence, WordPress Trac).
Successful exploitation exposes sensitive customer PII and transactional data, including full names, email addresses, phone numbers, billing and shipping addresses, order contents, and payment methods. Because no authentication is required and order IDs are typically sequential integers, an attacker can enumerate all orders on a vulnerable WooCommerce store, resulting in a full data breach of the store's customer base. The impact is limited to confidentiality — there is no integrity or availability impact — but the breadth of exposed data makes this a significant privacy and compliance risk (Wordfence, Red Hat CVE).
wp-content/plugins/oneclick-whatsapp-order/) using tools like Google dorks, Shodan, or WPScan.order_id or similar parameter.?order_id=1001 to ?order_id=1000, 999, etc.) to access other customers' order confirmation pages via the vulnerable wa_order_thank_you_override function./checkout/order-received/ or similar WooCommerce thank-you endpoints with varied order IDs and no associated authenticated session cookies.wa_order_thank_you_override endpoint.Update the OneClick Chat to Order plugin to version 1.0.9 or later, which includes the fix for this vulnerability (WordPress Trac Changeset). No configuration-based workaround is available; the only effective remediation is applying the patch. Site administrators should also audit web server access logs for signs of prior enumeration activity and consider notifying affected customers if exploitation is suspected.
The vulnerability was reported by Wordfence and received standard coverage from security aggregators and social media accounts focused on CVE tracking. RedPacketSecurity posted an alert on social media, and the CVE was noted on Bluesky and Mastodon by automated CVE-tracking accounts. A Medium article titled "CVE-2025-13526: 7 Lessons from the OneClick Chat to Order IDOR" was published, offering community analysis of the vulnerability's implications (RedPacket Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."