Right now in getOrderItems() function the requested variation ID is loaded based on SKU without any access checking.
Active
1.0
Code