CVE-2020-11497: High severity woocommerce vulnerability
An issue was discovered in the NAB Transact extension 2.1.0 for the WooCommerce plugin for WordPress. An online payment system bypass allows orders to be marked as fully paid by assigning an arbitrary bank transaction ID during the payment-details entry step.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-11497?
CVE-2020-11497 is an issue discovered in the NAB Transact extension 2.1.0 for the WooCommerce plugin for WordPress, allowing online payment system bypass.
What is the severity of CVE-2020-11497?
CVE-2020-11497 has a severity rating of 7.5 (High).
How does CVE-2020-11497 affect the NAB Transact extension?
CVE-2020-11497 affects the NAB Transact extension version 2.1.0 for the WooCommerce plugin for WordPress, allowing orders to be marked as fully paid by assigning an arbitrary bank transaction ID during the payment-details entry step.
How can I fix CVE-2020-11497?
To fix CVE-2020-11497, update the NAB Transact extension to a version that is not affected.
Is there any reference for CVE-2020-11497?
Yes, you can find the references for CVE-2020-11497 [here](http://packetstormsecurity.com/files/158931/WordPress-NAB-Transact-WooCommerce-2.1.0-Payment-Bypass.html), [here](http://seclists.org/fulldisclosure/2020/Aug/13), and [here](https://www.themissinglink.com.au/security-advisories-cve-2020-11497).