Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1
Critical0
High0
Medium1
Reset
Showing 1-1 of 1 records
Threat Entry Updated 2025-01-24

CVE-2023-2179 - Woocommerce Order Status Change Notifier Plugin

The WooCommerce Order Status Change Notifier WordPress plugin through 1.1.0 does not have authorisation and CSRF when updating status orders via an AJAX action available to any authenticated users, which could allow low privilege users such as subscriber to update arbitrary order status, making them paid without actually paying for them for example

PLUGIN Woocommerce Order Status Change Notifier

CVE-2023-2179

MEDIUM CVSS 6.5 2023-05-15
Scroll to top