CVE-2020-29156
EUVD-2022-565727.12.2020, 19:15
The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the order_id parameter in a fetch_order_status action.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| woocommerce | woocommerce | 𝑥 < 4.7.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration