{"api_version":"1","generated_at":"2026-07-23T13:09:14+00:00","cve":"CVE-2021-25002","urls":{"html":"https://cve.report/CVE-2021-25002","api":"https://cve.report/api/cve/CVE-2021-25002.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-25002","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-25002"},"summary":{"title":"CVE-2021-25002","description":"The Tipsacarrier WordPress plugin before 1.5.0.5 does not have any authorisation check in place some functions, which could allow unauthenticated users to access Orders data which could be used to retrieve the client full address, name and phone via tracking URL","state":"PUBLIC","assigner":"contact@wpscan.com","published_at":"2022-05-02 16:15:00","updated_at":"2022-10-27 20:19:00"},"problem_types":["CWE-862"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/b14f476e-3124-4cbf-91b4-ae53c4dabd7c","name":"https://wpscan.com/vulnerability/b14f476e-3124-4cbf-91b4-ae53c4dabd7c","refsource":"MISC","tags":[],"title":"Attention Required! | Cloudflare","mime":"text/html","httpstatus":"403","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-25002","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-25002","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"José Aguilera","lang":""}],"nvd_cpes":[{"cve_year":"2021","cve_id":"25002","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tipsacarrier_project","cpe5":"tipsacarrier","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"wordpress","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"25002","vulnerable":"1","versionEndIncluding":"1.4.4.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tipsacarrier_project","cpe5":"tipsacarrier","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"wordpress","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ID":"CVE-2021-25002","ASSIGNER":"contact@wpscan.com","STATE":"PUBLIC","TITLE":"Tipsacarrier < 1.5.0.5 - Unauthenticated Orders Disclosure"},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","generator":"WPScan CVE Generator","affects":{"vendor":{"vendor_data":[{"vendor_name":"Unknown","product":{"product_data":[{"product_name":"Tipsacarrier","version":{"version_data":[{"version_affected":"<","version_name":"1.5.0.5","version_value":"1.5.0.5"}]}}]}}]}},"description":{"description_data":[{"lang":"eng","value":"The Tipsacarrier WordPress plugin before 1.5.0.5 does not have any authorisation check in place some functions, which could allow unauthenticated users to access Orders data which could be used to retrieve the client full address, name and phone via tracking URL"}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://wpscan.com/vulnerability/b14f476e-3124-4cbf-91b4-ae53c4dabd7c","name":"https://wpscan.com/vulnerability/b14f476e-3124-4cbf-91b4-ae53c4dabd7c"}]},"problemtype":{"problemtype_data":[{"description":[{"value":"CWE-862 Missing Authorization","lang":"eng"}]}]},"credit":[{"lang":"eng","value":"José Aguilera"}],"source":{"discovery":"EXTERNAL"}},"nvd":{"publishedDate":"2022-05-02 16:15:00","lastModifiedDate":"2022-10-27 20:19:00","problem_types":["CWE-862"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:tipsacarrier_project:tipsacarrier:*:*:*:*:*:wordpress:*:*","versionEndExcluding":"1.5.0.5","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"25002","Ordinal":"199764","Title":"CVE-2021-25002","CVE":"CVE-2021-25002","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"25002","Ordinal":"1","NoteData":"** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.","Type":"Description","Title":null}]}}}