plugin

Admin And Client Message After Order For Woocommerce Vulnerabilities

15 known security issues reported for the Admin And Client Message After Order For Woocommerce WordPress plugin. Most recent disclosed Nov 25, 2025.

2 critical 2 high 6 medium

Running Admin And Client Message After Order For Woocommerce on your site? Check whether your installed version is affected.

Scan your site free

Admin and Customer Messages After Order for WooCommerce: OrderConvo [admin-and-client-message-after-order-for-woocommerce] <= 14 (unfixed)

unknown

[en] The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the `get_order_by_id()` function in all versions up to, and including, 14. This makes it possible for unauthenticated attackers to view sens...

Affected:
up to 14
Fix:
No patched version reported
Disclosed:
Nov 25, 2025

CVE-2025-13389 on NVD →

Admin and Customer Messages After Order for WooCommerce: OrderConvo [admin-and-client-message-after-order-for-woocommerce] <= 14 (unfixed)

unknown

[en] The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 14. This is due to a flawed permission check in the REST API permission callback that returns true when no nonce is provided. This makes it possi...

Affected:
up to 14
Fix:
No patched version reported
Disclosed:
Nov 25, 2025

CVE-2025-13452 on NVD →

Admin and Customer Messages After Order for WooCommerce: OrderConvo <= 14 - Missing Authorization to Unauthenticated Information Disclosure

medium

The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the `get_order_by_id()` function in all versions up to, and including, 14. This makes it possible for unauthenticated attackers to view sensitive...

CVSS:
5.3
Affected:
up to 14
Fixed in:
15
Disclosed:
Nov 24, 2025

CVE-2025-13389 on NVD →

Admin and Customer Messages After Order for WooCommerce: OrderConvo < 15 - Missing Authorization to Unauthenticated Information Disclosure

medium
Affected:
up to 15
Fixed in:
15
Disclosed:
Nov 24, 2025

CVE-2025-13389 on NVD →

Admin and Customer Messages After Order for WooCommerce: OrderConvo <= 14 - Missing Authorization to Unauthenticated User Impersonation in Order Messages

medium

The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 14. This is due to a flawed permission check in the REST API permission callback that returns true when no nonce is provided. This makes it possible f...

CVSS:
4.3
Affected:
up to 14
Fixed in:
15
Disclosed:
Nov 24, 2025

CVE-2025-13452 on NVD →

Admin and Customer Messages After Order for WooCommerce: OrderConvo < 15 - Missing Authorization to Unauthenticated User Impersonation in Order Messages

medium
Affected:
up to 15
Fixed in:
15
Disclosed:
Nov 24, 2025

CVE-2025-13452 on NVD →

Admin and Customer Messages After Order for WooCommerce: OrderConvo [admin-and-client-message-after-order-for-woocommerce] < 14 (closed)

unknown

[en] The Admin and Customer Messages After Order for WooCommerce: OrderConvo WordPress plugin before 14 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/download arbitrary files via a path traversal attack

Affected:
up to 14
Fixed in:
14
Disclosed:
Oct 7, 2025

CVE-2025-10162 on NVD →

Admin and Customer Messages After Order for WooCommerce: OrderConvo <= 13.5 - Unauthenticated Arbitrary File Read

high

The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 13.5 via the '/wp-json/wooconvo/v1/download-file' REST API. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on t...

CVSS:
7.5
Affected:
up to 13.5
Fixed in:
14
Disclosed:
Sep 16, 2025

CVE-2025-10162 on NVD →

OrderConvo < 14 - Unauthenticated Arbitrary File Read

high
Affected:
up to 14
Fixed in:
14
Disclosed:
Sep 16, 2025

CVE-2025-10162 on NVD →

Admin and Customer Messages After Order for WooCommerce: OrderConvo [admin-and-client-message-after-order-for-woocommerce] < 13.3 (closed)

unknown

[en] The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to limited file uploads due to insufficient file type validation in the upload_file() function in all versions up to, and including, 13.2. This makes it possible for authenticated attackers, with Subscriber-l...

Affected:
up to 13.3
Fixed in:
13.3
Disclosed:
Jan 16, 2025

CVE-2024-13355 on NVD →

Admin and Customer Messages After Order for WooCommerce <= 13.2 - Authenticated (Subscriber+) Limited File Upload to Cross-Site Scripting

medium

The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to limited file uploads due to insufficient file type validation in the upload_file() function in all versions up to, and including, 13.2. This makes it possible for authenticated attackers, with Subscriber-level...

CVSS:
5.4
Affected:
up to 13.2
Fixed in:
13.3
Disclosed:
Jan 15, 2025

CVE-2024-13355 on NVD →

Admin and Customer Messages After Order for WooCommerce < 13.3 - Authenticated (Subscriber+) Limited File Upload to Cross-Site Scripting

medium
Affected:
up to 13.3
Fixed in:
13.3
Disclosed:
Jan 15, 2025

CVE-2024-13355 on NVD →

Admin and Customer Messages After Order for WooCommerce: OrderConvo [admin-and-client-message-after-order-for-woocommerce] < 12.5 (closed)

unknown

[en] Missing Authorization vulnerability in N-Media OrderConvo allows OS Command Injection.This issue affects OrderConvo: from n/a through 12.4.

Affected:
up to 12.5
Fixed in:
12.5
Disclosed:
Apr 29, 2024

CVE-2024-33566 on NVD →

OrderConvo <= 12.4 - Missing Authorization to Arbitrary File Upload

critical

The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on a REST API endpoint in all versions up to, and including, 12.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the...

CVSS:
9.8
Affected:
up to 12.4
Fixed in:
12.5
Disclosed:
Apr 25, 2024

CVE-2024-33566 on NVD →

OrderConvo < 12.5 - Missing Authorization to Arbitrary File Upload

critical
Affected:
up to 12.5
Fixed in:
12.5
Disclosed:
Apr 25, 2024

CVE-2024-33566 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database