CVE-2020-29156
MEDIUMWooCommerce < 4.7.0 - Unauthenticated Arbitrary Order Status Disclosure via order_id Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-29156. PoCs published by Ko-kn3t.
AI-analyzed exploit summary The repository provides a technical description of CVE-2020-29156, an incorrect access control vulnerability in WooCommerce before 4.7.0. It explains how attackers can view arbitrary order statuses via the `order_id` parameter in the `fetch_order_status` endpoint.
Description
The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the order_id parameter in a fetch_order_status action.
Exploits (1)
The repository provides a technical description of CVE-2020-29156, an incorrect access control vulnerability in WooCommerce before 4.7.0. It explains how attackers can view arbitrary order statuses via the `order_id` parameter in the `fetch_order_status` endpoint.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N