PT-2026-6018 · Automattic+1 · Woocommerce+1
Md. Moniruzzaman Prodhan
+1
·
Published
2026-02-04
·
Updated
2026-02-04
·
CVE-2026-0679
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Fortis for WooCommerce versions up to and including 1.2.0
Description
The Fortis for WooCommerce plugin for WordPress has an authorization bypass issue because of an incorrect nonce check within the
check fortis notify response function. This allows unauthenticated attackers to modify WooCommerce order statuses to paid, processing, or completed, potentially enabling fraudulent order marking as paid without actual payment. The issue affects the wc-api endpoint.Recommendations
Update Fortis for WooCommerce to a version later than 1.2.0.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortis For Woocommerce
Woocommerce