WordPress Plugin Vulnerabilities

WooCommerce - NAB Transact < 2.1.2 - Payment Bypass

Description

The plugin does not validate the origin of payment processor status requests, allowing orders to be marked as fully paid by issuing a specially crafted GET request during the ordering workflow.

Proof of Concept

Affects Plugins

References

Miscellaneous

Original Researcher
Jack Misiura
Verified
No

Timeline

Publicly Published
2020-08-21 (about 5 years ago)
Added
2020-08-21 (about 5 years ago)
Last Updated
2020-08-22 (about 5 years ago)

Other