May 15, 2023, 1:15 p.m. |

National Vulnerability Database web.nvd.nist.gov

The WooCommerce Order Status Change Notifier WordPress plugin through 1.1.0 does not have authorisation and CSRF when updating status orders via an AJAX action available to any authenticated users, which could allow low privilege users such as subscriber to update arbitrary order status, making them paid without actually paying for them for example

1.1.0 action authorisation change csrf cve low making order paid plugin privilege update woocommerce wordpress wordpress plugin

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Information Security Engineers

@ D. E. Shaw Research | New York City

Security Officer Hospital Mission Viejo

@ Allied Universal | Mission Viejo, CA, United States

Junior Offensive Cyber Security Researcher

@ Draper | Cambridge, MA, United States

Consultant reporting reglementaire

@ Talan | Luxembourg, Luxembourg

Chief Information Security Officer

@ Kantox | Barcelona, Catalonia, Spain