CVE-2025-13457: Woocommerce Square
High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.
The WooCommerce Square plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.1 via the get_token_by_id function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to expose arbitrary Square "ccof" (credit card on file) values and leverage this value to potentially make fraudulent charges on the target site.
Affected products
- Woocommerce Woocommerce Square: from 4.2.0, before 4.2.3 (fixed in 4.2.3); from 4.3.0, before 4.3.2 (fixed in 4.3.2); from 4.4.0, before 4.4.2 (fixed in 4.4.2); from 4.5.0, before 4.5.2 (fixed in 4.5.2); from 4.6.0, before 4.6.4 (fixed in 4.6.4); from 4.7.0, before 4.7.4 (fixed in 4.7.4); …
Published 2026-01-10. Last modified 2026-06-17.