PT-2020-17101 · WordPress · Woocommerce
Published
2020-12-27
·
Updated
2024-03-22
·
CVE-2020-29156
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WooCommerce plugin versions prior to 4.7.0
Description
The issue allows remote attackers to view the status of arbitrary orders via the
order id parameter in a fetch order status action. This could potentially expose sensitive information about orders.Recommendations
For versions prior to 4.7.0, update to version 4.7.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the
fetch order status action to minimize the risk of exploitation. Avoid using the order id parameter in the affected action until the issue is resolved.Exploit
Fix
Incorrect Authorization
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Woocommerce