CVE-2020-11497
HIGHNAB Transact WooCommerce Extension 2.1.0 - Payment Bypass via Arbitrary Transaction ID
Title source: llmDescription
An issue was discovered in the NAB Transact extension 2.1.0 for the WooCommerce plugin for WordPress. An online payment system bypass allows orders to be marked as fully paid by assigning an arbitrary bank transaction ID during the payment-details entry step.
References (3)
Core 3
Core References
Exploit, Third Party Advisory x_refsource_misc
https://www.themissinglink.com.au/security-advisories-cve-2020-11497
Exploit, Mailing List, Third Party Advisory mailing-list
x_refsource_fulldisc
http://seclists.org/fulldisclosure/2020/Aug/13
Third Party Advisory x_refsource_misc
http://packetstormsecurity.com/files/158931/WordPress-NAB-Transact-WooCommerce-2.1.0-Payment-Bypass.html
Scores
CVSS v3
7.5
EPSS
0.0115
EPSS Percentile
62.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Details
CWE
CWE-354
Status
published
Products (1)
woocommerce/nab_transact
2.1.0
Published
Aug 26, 2020
Tracked Since
Feb 18, 2026