CVE-2023-2179

T

he WooCommerce Order Status Change Notifier WordPress plugin through 1.1.0 does not have authorisation and CSRF when updating status orders via an AJAX action available to any authenticated users, which could allow low privilege users such as subscriber to update arbitrary order status, making them paid without actually paying for them for example

Configurations

Configuration 1 (hide)

cpe:2.3:a:woocommerce:woocommerce_order_status_change_notifier:*:*:*:*:*:wordpress:*:*

History

21 Nov 2024, 07:58

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/fbc56973-4225-4f44-8c38-d488e57cd551 - Exploit () https://wpscan.com/vulnerability/fbc56973-4225-4f44-8c38-d488e57cd551 - Exploit

Information

Published : 2023-05-15 13:15

Updated : 2025-01-24 21:15


NVD link : CVE-2023-2179

Mitre link : CVE-2023-2179

CVE.ORG link : CVE-2023-2179


JSON object : View

CWE

No CWE.