WooCommerce Incorrect Authorization
Moderate severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Jan 10, 2024
Description
Published by the National Vulnerability Database
Dec 27, 2020
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
Jan 10, 2024
Last updated
Jan 10, 2024
The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the
order_id
parameter in afetch_order_status
action.References