WPC Order Tip for WooCommerce <= 3.3.0 - Information Exposure to Unauthenticated Order Data Disclosure
mediumThe WPC Order Tip for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 3.3.0. This is due to missing capability check and nonce verification on the wpcot_display_reports AJAX handler. This makes it possible for unauthenticated attackers to access order t...
- CVSS:
- 5.3
- Affected:
- up to 3.3.0
- Fixed in:
- 3.3.1
- Disclosed:
- Aug 3, 2026