CVE-2023-2179

CVE-2023-2179: WooCommerce Order Status Change Notifier <= 1.1.0 - Subscriber+ Arbitrary Order Status Update

Vendor Unknown
Product WooCommerce Order Status Change Notifier
Published May 15, 2023
Last update January 24, 2025

CVSS base score

What the vulnerability does

01Description

The WooCommerce Order Status Change Notifier WordPress plugin through 1.1.0 does not have authorisation and CSRF when updating status orders via an AJAX action available to any authenticated users, which could allow low privilege users such as subscriber to update arbitrary order status, making them paid without actually paying for them for example

Key dates

02Disclosure timeline

May 15, 2023 CVE published
January 24, 2025 Record updated