CVE-2025-14073
Published: Sat, 01 Aug 2026 09:16
Summary
The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information Disclosure due to an Insecure Direct Object Reference in all versions up to, and including, 3.3.2 via the `e
Details
The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information Disclosure due to an Insecure Direct Object Reference in all versions up to, and including, 3.3.2 via the `enqueue_paypal_insights_script_on_order_received()` function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to obtain sensitive order information including order keys, which can then be leveraged to access full customer billing details (name, email, phone, address) via the WooCommerce Store API within a 10-minute grace period after order creation.
Are YOU affected by CVE-2025-14073?
5-second check on your actual server. Reads /etc/os-release, uname -r, and dpkg-query; matches against the live USN + Debian Security Tracker feeds; tells you whether CVE-2025-14073 (and any other live CVE) applies. Anonymous, no signup.
curl https://mindsparkstack.com/scan.sh | bash
References
- https://plugins.trac.wordpress.org/browser/woocommerce-paypal-payments/tags/3.3.0/modules/ppcp-axo/src/AxoModule.php#L362
- https://plugins.trac.wordpress.org/changeset/3458079/woocommerce-paypal-payments/trunk/modules/ppcp-axo/src/AxoModule.php
- https://plugins.trac.wordpress.org/changeset?old_path=%2Fwoocommerce-paypal-payments/tags/3.3.2&new_path=%2Fwoocommerce-paypal-payments/tags/3.4.0
- https://www.wordfence.com/threat-intel/vulnerabilities/id/a2919bbc-c4c2-4b52-90ec-2471218cd7d1?source=cve
StackPatch runs this match against YOUR installed packages every hour
Free (3 servers) / from $9/mo (14-day free trial) / Solo $9/mo / Pro $29/mo / Team $79/mo. Indie pricing.