CVE-2023-2179

The WooCommerce Order Status Change Notifier WordPress plugin through 1.1.0 does not have authorisation and CSRF when updating status orders via an AJAX action available to any authenticated users, which could allow low privilege users such as subscriber to update arbitrary order status, making them paid without actually paying for them for example
Configurations

Configuration 1 (hide)

cpe:2.3:a:woocommerce:woocommerce_order_status_change_notifier:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 07:58

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/fbc56973-4225-4f44-8c38-d488e57cd551 - Exploit () https://wpscan.com/vulnerability/fbc56973-4225-4f44-8c38-d488e57cd551 - Exploit

07 Nov 2023, 04:12

Type Values Removed Values Added
CWE CWE-862
CWE-352

Information

Published : 2023-05-15 13:15

Updated : 2024-11-21 07:58


NVD link : CVE-2023-2179

Mitre link : CVE-2023-2179

CVE.ORG link : CVE-2023-2179


JSON object : View

Products Affected

woocommerce

  • woocommerce_order_status_change_notifier
CWE

No CWE.