WordPress Plugin Vulnerabilities
WooCommerce - NAB Transact < 2.1.2 - Payment Bypass
Description
The plugin does not validate the origin of payment processor status requests, allowing orders to be marked as fully paid by issuing a specially crafted GET request during the ordering workflow.
Proof of Concept
Affects Plugins
References
Miscellaneous
Original Researcher
Jack Misiura
Verified
No
WPVDB ID
Timeline
Publicly Published
2020-08-21 (about 5 years ago)
Added
2020-08-21 (about 5 years ago)
Last Updated
2020-08-22 (about 5 years ago)