The WooCommerce Order Status Change Notifier WordPress plugin through 1.1.0 does not have authorisation and CSRF when updating status orders via an AJAX action available to any authenticated users, which could allow low privilege users such as subscriber to update arbitrary order status, making them paid without actually paying for them for example
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 07:58
Type | Values Removed | Values Added |
---|---|---|
References | () https://wpscan.com/vulnerability/fbc56973-4225-4f44-8c38-d488e57cd551 - Exploit |
07 Nov 2023, 04:12
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-352 |
Information
Published : 2023-05-15 13:15
Updated : 2024-11-21 07:58
NVD link : CVE-2023-2179
Mitre link : CVE-2023-2179
CVE.ORG link : CVE-2023-2179
JSON object : View
Products Affected
woocommerce
- woocommerce_order_status_change_notifier
CWE
No CWE.