THREAT OPS › Threat News › [NVD] CVE-2025-14073 (MEDIUM 5.3) — The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information Disclosure due to an Insecure Direct Object Reference in all versions up to, and including, 3.3.2 via the `enqueue_paypal_insights_script_on_order_received()` function due to missing valid
[NVD] CVE-2025-14073 (MEDIUM 5.3) — The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information Disclosure due to an Insecure Direct Object Reference in all versions up to, and including, 3.3.2 via the `enqueue_paypal_insights_script_on_order_received()` function due to missing valid
CVE-2025-14073 CVSS: 5.3 MEDIUM Published: 2026-08-01T09:16:57.240
The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information Disclosure due to an Insecure Direct Object Reference in all versions up to, and including, 3.3.2 via the `enqueue_paypal_insights_script_on_order_received()` function due to missing validation on a user controlled key. This makes it possib
Indicators of compromise
- CVE-2025-14073cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-14073