Описание
WooCommerce Incorrect Authorization
The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the order_id parameter in a fetch_order_status action.
Пакеты
Наименование
woocommerce/woocommerce
composer
Затронутые версииВерсия исправления
< 4.7.0
4.7.0
Связанные уязвимости
CVSS3: 5.3
nvd
около 5 лет назад
The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the order_id parameter in a fetch_order_status action.