Executive brief
The Order Sync with Zendesk for WooCommerce plugin integrates WooCommerce store order data with Zendesk customer support systems. An unauthenticated attacker who knows a customer's email address can bypass authentication checks and retrieve sensitive order information including purchase history, spending totals, and payment methods through an unsecured REST API endpoint.
Technical details
The plugin fails to perform capability checks and ownership verification on its REST API endpoint `/wp-json/zndskwoo/order_details`. An unauthenticated attacker can send a GET request with a target customer's email address as a parameter to retrieve sensitive order data including order counts, average order value, total spending, and complete order history. No authentication, cookies, nonces, or special configuration is required beyond the plugin being active alongside WooCommerce. This results in information disclosure (CWE-200) allowing attackers to enumerate customer purchasing patterns and financial data. The vulnerability is fixed in version 2.2.3.
Affected products
- MakWebPro Order Sync with Zendesk for WooCommerce before 2.2.3
Timeline
- 2026-08-10: disclosed
- 2026-08-12: patched: Fixed in version 2.2.3