CVE Database
/

CVE-2023-2179

Back to search

CVE-2023-2179

Published: May 15, 2023

Modified: Jan 24, 2025

PUBLISHED

Description

The WooCommerce Order Status Change Notifier WordPress plugin through 1.1.0 does not have authorisation and CSRF when updating status orders via an AJAX action available to any authenticated users, which could allow low privilege users such as subscriber to update arbitrary order status, making them paid without actually paying for them for example

VendorProductVersions

Unknown

WooCommerce Order Status Change Notifier

affected
0 - <= 1.1.0

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now