"The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the order_id parameter in a fetch_order_status action."
https://example.com/wp-admin/admin-ajax.php?action=fetch_order_status&order_id=XX
2020-12-28 (about 2 years ago)
2021-02-22 (about 1 years ago)
2021-02-23 (about 1 years ago)