Order Tip for WooCommerce <= 1.5.4 - Unauthenticated Tip Manipulation to Negative Value Leading to Unauthorized Discounts

2025-08-14 13:51
t.t.brothers

Strategic Overview

Status
Patched in 1.5.5
Affected Version<= 1.5.4
CVSS7.5High
CVECVE-2025-6025
View all Order Tip for WooCommerce vulnerabilities

Vulnerability Overview

The Order Tip for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Improper Input Validation in all versions up to, and including, 1.5.4. This is due to lack of server-side validation on the `data-tip` attribute, which makes it possible for unauthenticated attackers to apply an excessive or even negative tip amount, resulting in unauthorized discount up to free orders depending on the value submitted.

Technical Analysis

REMEDIATION: Update to version 1.5.5, or a newer patched version --- IDENTIFIER: CWE-602 (Client-Side Enforcement of Server-Side Security) The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C