Vulnerabilities
CVE-2025-13457 - WooCommerce Square <= 5.1.1 - unauthenticated insecure direct object reference t
CVE ID : CVE-2025-13457 Published : Jan. 10, 2026, 4:15 a.m. | 1 hour, 19 minutes ago Description : The WooCommerce Square plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.1 via the get_token_by_id function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to expose arbitrary Square
Source: Telegram CVE Monitor