Executive brief
The APIExperts Square for WooCommerce plugin, which integrates Square payment processing with WordPress online stores, contains a security flaw that exposes sensitive information. An unauthorized attacker can access data that should be private, potentially leading to further compromise of the store or customer information. This vulnerability could be used in automated attacks against thousands of websites simultaneously.
Technical details
The APIExperts Square for WooCommerce plugin (versions up to 4.7.3) is vulnerable to CWE-201: Insertion of Sensitive Information Into Sent Data. This flaw allows an unauthenticated remote attacker to retrieve sensitive data that is inadvertently embedded in the data sent by the application. The vulnerability has a CVSS 3.1 score of 8.3, reflecting its high impact and ease of exploitation over the network without user interaction. Attackers can leverage this exposed information to facilitate further attacks or gain unauthorized insights into the system's configuration or user data. A fix is available in version 4.7.4.
Affected products
- Saad Iqbal APIExperts Square for WooCommerce up to 4.7.3
Timeline
- 2026-04-29: other: Vulnerability reported by Peng Zhou
- 2026-06-18: advisory: Patchstack published advisory
- 2026-06-25: disclosed: CVE published to NVD
- 2026-06-25: patched: Version 4.7.4 released to address the issue