CVE-2025-15033
Description
A vulnerability in WooCommerce 8.1 to 10.4.2 can allow logged-in customers to access order data of guest customers on sites with a certain configuration. This has been fixed in WooCommerce 10.4.3, as well as all the previously affected versions through point releases, starting from 8.1, where it has been fixed in 8.1.3. It does not affect WooCommerce 8.0 or earlier.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
In WooCommerce 8.1 to 10.4.2, logged-in customers could access guest customer order data under certain configurations; fixed in subsequent point releases.
Vulnerability
Overview
A vulnerability in the WooCommerce plugin for WordPress, affecting versions 8.1 through 10.4.2, allows logged-in users with customer-level privileges to access order data belonging to guest customers on sites with a specific configuration [1]. The issue is classified as a sensitive data disclosure flaw and was discovered by researcher Peter Stöckli [1].
Exploitation
Conditions
The attack requires the attacker to be a logged-in customer on the WooCommerce site. The vulnerability only manifests when the site is configured in a certain way, though the exact configuration detail is not publicly specified in the advisory [1]. No additional authentication or network position is required beyond being an authenticated customer.
Impact
A successful exploit could expose private order information of guest customers, including potentially sensitive details like names, addresses, and purchased items [1]. This leakage violates the expected separation between user accounts and guest orders, undermining customer trust and potentially violating data protection regulations.
Mitigation
The vulnerability has been fully addressed by WooCommerce. Patched versions have been released across all affected minor branches, starting from 8.1.3 up to 10.4.3 [1]. Users running any affected version should update immediately to the corresponding fixed release. No workarounds have been published.
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.