CVE 7.5 HIGH

WooCommerce Square <= 5.1.1 - Unauthenticated Insecure Direct Object Reference to Sensitive Information Exposure in get_token_by_id_CVE-2025-13457

7.5 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

The WooCommerce Square plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.1 via the get_token_by_id function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to expose arbitrary Square "ccof" (credit card on file) values and leverage this value to potentially make fraudulent charges on the target site.

Basic Information

ID CVE-2025-13457
Source Wordfence
Published Jan 10, 2026 at 03:21

Affected Product

Vendor woocommerce
Product WooCommerce Square
Version 4.2.0
Affected Versions woocommerce WooCommerce Square 4.2.0
woocommerce WooCommerce Square 4.3.0
woocommerce WooCommerce Square 4.4.0
woocommerce WooCommerce Square 4.5.0
woocommerce WooCommerce Square 4.6.0
woocommerce WooCommerce Square 4.7.0
woocommerce WooCommerce Square 4.8.0
woocommerce WooCommerce Square 4.9.0
woocommerce WooCommerce Square 5.0.0
woocommerce WooCommerce Square 5.1.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.