plugin

Woocommerce Square Vulnerabilities

4 known security issues reported for the Woocommerce Square WordPress plugin. Most recent disclosed Jan 10, 2026.

1 high 1 medium

Running Woocommerce Square on your site? Check whether your installed version is affected.

Scan your site free

WooCommerce Square [woocommerce-square] <= 5.1.1 (unfixed)

unknown

[en] The WooCommerce Square plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.1 via the get_token_by_id function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to expose arbitrary Square "ccof" (cre...

Affected:
up to 5.1.1
Fix:
No patched version reported
Disclosed:
Jan 10, 2026

CVE-2025-13457 on NVD →

WooCommerce Square <= 5.1.1 - Unauthenticated Insecure Direct Object Reference to Sensitive Information Exposure in get_token_by_id

high

The WooCommerce Square plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.1 via the get_token_by_id function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to expose arbitrary Square "ccof" (credit c...

CVSS:
7.5
Affected:
4.2.0 – 4.2.3, 4.3.0 – 4.3.2, 4.4.0 – 4.4.2, 4.5.0 – 4.5.2, 4.6.0 – 4.6.4, 4.7.0 – 4.7.4, 4.8.0 – 4.8.8, 4.9.0 – 4.9.9, 5.0.0 – 5.0.1, 5.1.0 – 5.1.2
Fixed in:
4.2.3
Disclosed:
Jan 9, 2026

CVE-2025-13457 on NVD →

WooCommerce Square [woocommerce-square] < 3.8.2

unknown

[en] Authorization Bypass Through User-Controlled Key vulnerability in WooCommerce WooCommerce Square.This issue affects WooCommerce Square: from n/a through 3.8.1.

Affected:
up to 3.8.2
Fixed in:
3.8.2
Disclosed:
Dec 20, 2023

CVE-2023-35876 on NVD →

WooCommerce Square <= 3.8.1 - Missing Authorization via multiple AJAX actions

medium

The WooCommerce Square plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple AJAX functions in versions up to, and including, 3.8.1. This makes it possible for authenticated attackers with contributor-level privileges to modify other user's orders.

CVSS:
4.3
Affected:
up to 3.8.1
Fixed in:
3.8.2
Disclosed:
Jun 19, 2023

CVE-2023-35876 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database