CVE-2023-2179

The WooCommerce Order Status Change Notifier WordPress plugin through 1.1.0 does not have authorisation and CSRF when updating status orders via an AJAX action available to any authenticated users, which could allow low privilege users such as subscriber to update arbitrary order status, making them paid without actually paying for them for example
Configurations

Configuration 1 (hide)

cpe:2.3:a:woocommerce:woocommerce_order_status_change_notifier:*:*:*:*:*:wordpress:*:*

History

23 May 2023, 18:18

Type Values Removed Values Added
References (MISC) https://wpscan.com/vulnerability/fbc56973-4225-4f44-8c38-d488e57cd551 - (MISC) https://wpscan.com/vulnerability/fbc56973-4225-4f44-8c38-d488e57cd551 - Exploit
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CPE cpe:2.3:a:woocommerce:woocommerce_order_status_change_notifier:*:*:*:*:*:wordpress:*:*

15 May 2023, 13:26

Type Values Removed Values Added
New CVE

Information

Published : 2023-05-15 13:15

Updated : 2024-02-04 23:37


NVD link : CVE-2023-2179

Mitre link : CVE-2023-2179

CVE.ORG link : CVE-2023-2179


JSON object : View

Products Affected

woocommerce

  • woocommerce_order_status_change_notifier
CWE

No CWE.