What is CVE-2025-14073?
The WooCommerce PayPal Payments plugin for WordPress, up to version 3.3.2, suffers from a Sensitive Information Disclosure vulnerability due to an Insecure Direct Object Reference in the `enqueue_paypal_insights_script_on_order_received()` function. This can lead to the exposure of sensitive data; immediate update to the latest plugin version is recommended.
Azərbaycanca: WooCommerce PayPal Payments plugin-inin 3.3.2-yə qədər versiyalarında `enqueue_paypal_insights_script_on_order_received()` funksiyasındakı Insecure Direct Object Reference zəifliyi vasitəsilə həssas məlumat ifşası müşahidə olunur. Bu, səhifədə məxfiliyi qorunmalı olan məlumatların sızmasına səbəb ola bilər; təcili olaraq plugini son versiyaya yeniləmək tövsiyə olunur.
FAQ2
Which version of the WooCommerce PayPal Payments plugin is affected by the Insecure Direct Object Reference vulnerability?
The vulnerability affects versions up to 3.3.2 of the plugin. Immediate update to the latest version is recommended.
Which function triggers the Sensitive Information Disclosure in CVE-2025-14073?
The vulnerability is triggered through an Insecure Direct Object Reference in the `enqueue_paypal_insights_script_on_order_received()` function.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.