WooCommerce Square [woocommerce-square] <= 5.1.1 (unfixed)
unknown[en] The WooCommerce Square plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.1 via the get_token_by_id function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to expose arbitrary Square "ccof" (cre...
- Affected:
- up to 5.1.1
- Fix:
- No patched version reported
- Disclosed:
- Jan 10, 2026