CVE-2020-11497

HIGH

NAB Transact WooCommerce Extension 2.1.0 - Payment Bypass via Arbitrary Transaction ID

Title source: llm
STIX 2.1

Description

An issue was discovered in the NAB Transact extension 2.1.0 for the WooCommerce plugin for WordPress. An online payment system bypass allows orders to be marked as fully paid by assigning an arbitrary bank transaction ID during the payment-details entry step.

References (3)

Core 3
Core References
Exploit, Third Party Advisory x_refsource_misc
https://www.themissinglink.com.au/security-advisories-cve-2020-11497
Exploit, Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2020/Aug/13

Scores

CVSS v3 7.5
EPSS 0.0115
EPSS Percentile 62.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-354
Status published
Products (1)
woocommerce/nab_transact 2.1.0
Published Aug 26, 2020
Tracked Since Feb 18, 2026