cleantalk
Vulnerabilities and Security Researches

Order Tip for WooCommerce, CVE-2025-6025

CVE, Research URL

CVE-2025-6025

Published on
Aug 15, 2025
Research Description
The Order Tip for WooCommerce plugin for WordPress is vulnerable to Unauthenticated Improper Input Validation in all versions up to, and including, 1.5.4. This is due to lack of server-side validation on the `data-tip` attribute, which makes it possible for unauthenticated attackers to apply an excessive or even negative tip amount, resulting in unauthorized discount up to free orders depending on the value submitted.
Affected versions
Min -, max 1.5.5.
Status
vulnerable