Admin and Customer Messages After Order for WooCommerce: OrderConvo [admin-and-client-message-after-order-for-woocommerce] <= 14 (unfixed)
unknown
[en] The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the `get_order_by_id()` function in all versions up to, and including, 14. This makes it possible for unauthenticated attackers to view sens...
- Affected:
- up to 14
- Fix:
- No patched version reported
- Disclosed:
- Nov 25, 2025
CVE-2025-13389 on NVD →
Admin and Customer Messages After Order for WooCommerce: OrderConvo [admin-and-client-message-after-order-for-woocommerce] <= 14 (unfixed)
unknown
[en] The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 14. This is due to a flawed permission check in the REST API permission callback that returns true when no nonce is provided. This makes it possi...
- Affected:
- up to 14
- Fix:
- No patched version reported
- Disclosed:
- Nov 25, 2025
CVE-2025-13452 on NVD →
Admin and Customer Messages After Order for WooCommerce: OrderConvo <= 14 - Missing Authorization to Unauthenticated Information Disclosure
medium
The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the `get_order_by_id()` function in all versions up to, and including, 14. This makes it possible for unauthenticated attackers to view sensitive...
- CVSS:
- 5.3
- Affected:
- up to 14
- Fixed in:
- 15
- Disclosed:
- Nov 24, 2025
CVE-2025-13389 on NVD →
Admin and Customer Messages After Order for WooCommerce: OrderConvo < 15 - Missing Authorization to Unauthenticated Information Disclosure
medium
- Affected:
- up to 15
- Fixed in:
- 15
- Disclosed:
- Nov 24, 2025
CVE-2025-13389 on NVD →
Admin and Customer Messages After Order for WooCommerce: OrderConvo <= 14 - Missing Authorization to Unauthenticated User Impersonation in Order Messages
medium
The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 14. This is due to a flawed permission check in the REST API permission callback that returns true when no nonce is provided. This makes it possible f...
- CVSS:
- 4.3
- Affected:
- up to 14
- Fixed in:
- 15
- Disclosed:
- Nov 24, 2025
CVE-2025-13452 on NVD →
Admin and Customer Messages After Order for WooCommerce: OrderConvo < 15 - Missing Authorization to Unauthenticated User Impersonation in Order Messages
medium
- Affected:
- up to 15
- Fixed in:
- 15
- Disclosed:
- Nov 24, 2025
CVE-2025-13452 on NVD →
Admin and Customer Messages After Order for WooCommerce: OrderConvo [admin-and-client-message-after-order-for-woocommerce] < 14 (closed)
unknown
[en] The Admin and Customer Messages After Order for WooCommerce: OrderConvo WordPress plugin before 14 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/download arbitrary files via a path traversal attack
- Affected:
- up to 14
- Fixed in:
- 14
- Disclosed:
- Oct 7, 2025
CVE-2025-10162 on NVD →
Admin and Customer Messages After Order for WooCommerce: OrderConvo <= 13.5 - Unauthenticated Arbitrary File Read
high
The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 13.5 via the '/wp-json/wooconvo/v1/download-file' REST API. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on t...
- CVSS:
- 7.5
- Affected:
- up to 13.5
- Fixed in:
- 14
- Disclosed:
- Sep 16, 2025
CVE-2025-10162 on NVD →
OrderConvo < 14 - Unauthenticated Arbitrary File Read
high
- Affected:
- up to 14
- Fixed in:
- 14
- Disclosed:
- Sep 16, 2025
CVE-2025-10162 on NVD →
Admin and Customer Messages After Order for WooCommerce: OrderConvo [admin-and-client-message-after-order-for-woocommerce] < 13.3 (closed)
unknown
[en] The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to limited file uploads due to insufficient file type validation in the upload_file() function in all versions up to, and including, 13.2. This makes it possible for authenticated attackers, with Subscriber-l...
- Affected:
- up to 13.3
- Fixed in:
- 13.3
- Disclosed:
- Jan 16, 2025
CVE-2024-13355 on NVD →
Admin and Customer Messages After Order for WooCommerce <= 13.2 - Authenticated (Subscriber+) Limited File Upload to Cross-Site Scripting
medium
The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to limited file uploads due to insufficient file type validation in the upload_file() function in all versions up to, and including, 13.2. This makes it possible for authenticated attackers, with Subscriber-level...
- CVSS:
- 5.4
- Affected:
- up to 13.2
- Fixed in:
- 13.3
- Disclosed:
- Jan 15, 2025
CVE-2024-13355 on NVD →
Admin and Customer Messages After Order for WooCommerce < 13.3 - Authenticated (Subscriber+) Limited File Upload to Cross-Site Scripting
medium
- Affected:
- up to 13.3
- Fixed in:
- 13.3
- Disclosed:
- Jan 15, 2025
CVE-2024-13355 on NVD →
Admin and Customer Messages After Order for WooCommerce: OrderConvo [admin-and-client-message-after-order-for-woocommerce] < 12.5 (closed)
unknown
[en] Missing Authorization vulnerability in N-Media OrderConvo allows OS Command Injection.This issue affects OrderConvo: from n/a through 12.4.
- Affected:
- up to 12.5
- Fixed in:
- 12.5
- Disclosed:
- Apr 29, 2024
CVE-2024-33566 on NVD →
OrderConvo <= 12.4 - Missing Authorization to Arbitrary File Upload
critical
The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on a REST API endpoint in all versions up to, and including, 12.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the...
- CVSS:
- 9.8
- Affected:
- up to 12.4
- Fixed in:
- 12.5
- Disclosed:
- Apr 25, 2024
CVE-2024-33566 on NVD →
OrderConvo < 12.5 - Missing Authorization to Arbitrary File Upload
critical
- Affected:
- up to 12.5
- Fixed in:
- 12.5
- Disclosed:
- Apr 25, 2024
CVE-2024-33566 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database