CVE-2020-11497

HIGH

NAB Transact <2.1.0 - Auth Bypass

Title source: llm
STIX 2.1

Description

An issue was discovered in the NAB Transact extension 2.1.0 for the WooCommerce plugin for WordPress. An online payment system bypass allows orders to be marked as fully paid by assigning an arbitrary bank transaction ID during the payment-details entry step.

Scores

CVSS v3 7.5
EPSS 0.0010
EPSS Percentile 26.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-354
Status published
Products (1)
woocommerce/nab_transact 2.1.0
Published Aug 26, 2020
Tracked Since Feb 18, 2026