QID 150378

Date Published: 2021-10-29

QID 150378: WordPress Woocommerce plugin Arbitrary orders enumeration (CVE-2020-29156)

WordPress is an open-source blogging tool and content management system based on PHP and MySQL. It has many features including a plug-in architecture and a template system.

The plugin before 4.7.0 allows remote attackers to view the status of arbitrary orders via the order_id parameter in fetch_order_status.

Affected Versions:
WooCommerce plugins before 4.7.0 for WordPress are affected.

Successful exploitation could allow remote attackers to view status of arbitrary orders.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to upgrade to a fixed version WooCommerce plugin 4.7.0 or later versions to remediate this vulnerability.

    CVEs related to QID 150378

    Software Advisories
    Advisory ID Software Component Link
    Woocommerce URL Logo wordpress.org/plugins/woocommerce/