CVE-2025-49356
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-49356 is a Missing Authorization (Broken Access Control) vulnerability in the "Orders Chat for WooCommerce" WordPress plugin developed by Mykola Lukin. It allows authenticated low-privileged users (e.g., subscribers) to access other customers' chat data and order information by exploiting incorrectly configured access control security levels. The vulnerability affects all plugin versions through 1.2.0 (per the CVE description) and up to 2.0.0 per Patchstack's database. It was reported on October 16, 2025, and publicly disclosed on December 31, 2025, with a CVSS v3.1 base score of 4.3 (Medium) (Patchstack, Red Hat CVE).

Technical details

The root cause is classified as CWE-862 (Missing Authorization), meaning the plugin fails to properly verify whether an authenticated user has the appropriate permissions before granting access to order chat data. An attacker with a low-privileged WordPress account (e.g., a subscriber or customer) can send crafted requests to plugin endpoints that lack proper authorization checks, thereby accessing chat messages and order details belonging to other customers. No nonce token or capability check is enforced on the vulnerable function, which maps to OWASP Top 10 category A1: Broken Access Control (Patchstack).

Impact

Successful exploitation results in unauthorized read access to other customers' order chat communications and potentially associated order details, representing a confidentiality breach. There is no integrity or availability impact — the vulnerability is limited to information disclosure. While the scope is constrained to the plugin's data, exposure of customer communications could violate privacy regulations and erode user trust on affected WooCommerce stores (Patchstack, Red Hat CVE).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.025% (0.000250), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack classifies this as low priority and notes it is unlikely to be exploited, though it acknowledges that broken access control vulnerabilities are sometimes used in mass-exploit campaigns targeting WordPress plugins at scale (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the "Orders Chat for WooCommerce" plugin (version ≤ 2.0.0) using tools like WPScan or by checking plugin metadata in publicly accessible WordPress installations.
  2. Obtain low-privileged access: Register or log in as a subscriber or customer-level account on the target WooCommerce store.
  3. Identify vulnerable endpoint: Locate the plugin's AJAX or REST API endpoint responsible for retrieving order chat data (e.g., a WordPress admin-ajax.php action or REST route registered by the plugin without proper capability checks).
  4. Send unauthorized request: Craft an HTTP request to the vulnerable endpoint, supplying another customer's order ID or chat identifier as a parameter, without possessing the authorization to view that order.
  5. Access sensitive data: The server returns the targeted customer's chat messages and order information due to the missing authorization check, completing the unauthorized data access (Patchstack).

Indicators of compromise

  • Logs: WordPress access logs showing repeated requests to admin-ajax.php or plugin-specific REST API endpoints from a single authenticated low-privileged user account, particularly with varying order IDs in request parameters.
  • Logs: Unusual patterns of authenticated requests to order chat retrieval endpoints outside of normal business hours or from unexpected geographic locations.
  • Network: High-frequency authenticated HTTP GET/POST requests to WooCommerce order chat endpoints from a single session or IP address, suggesting enumeration of order IDs.

Mitigation and workarounds

Patchstack's database indicates no official patch is currently available from the plugin developer, and the vulnerable versions extend through 2.0.0. Site administrators should consider deactivating and removing the "Orders Chat for WooCommerce" plugin until a patched version is released. As a compensating control, Patchstack's virtual patching (firewall rules) can be used to block exploitation attempts without requiring a plugin update (Patchstack). Administrators should also review user roles and restrict plugin access to trusted roles only where possible.

Community reactions

The vulnerability was discovered by security researcher "powpy" and reported to Patchstack on October 16, 2025, before public disclosure on December 31, 2025. Patchstack issued an early warning to its customers upon disclosure. No significant broader media coverage or notable researcher commentary beyond the Patchstack advisory has been identified (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18603NONEN/A
  • cancel-order-request-woocommerce
NoYesAug 09, 2026
CVE-2026-18473NONEN/A
  • wpdirectorykit
NoYesAug 09, 2026
CVE-2026-18465NONEN/A
  • wp-google-map-gold
NoYesAug 09, 2026
CVE-2026-18464NONEN/A
  • wp-google-map-gold
NoYesAug 09, 2026
CVE-2026-18357NONEN/A
  • wpc-order-tip
NoYesAug 09, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management