THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-14073 (MEDIUM 5.3) — The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information Disclosure due to an Insecure Direct Object Reference in all versions up to, and including, 3.3.2 via the `enqueue_paypal_insights_script_on_order_received()` function due to missing valid

[NVD] CVE-2025-14073 (MEDIUM 5.3) — The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information Disclosure due to an Insecure Direct Object Reference in all versions up to, and including, 3.3.2 via the `enqueue_paypal_insights_script_on_order_received()` function due to missing valid

mednvdPublished 2026-08-01

CVE-2025-14073 CVSS: 5.3 MEDIUM Published: 2026-08-01T09:16:57.240

The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information Disclosure due to an Insecure Direct Object Reference in all versions up to, and including, 3.3.2 via the `enqueue_paypal_insights_script_on_order_received()` function due to missing validation on a user controlled key. This makes it possib

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-14073