First published: Wed Aug 26 2020(Updated: )
An issue was discovered in the NAB Transact extension 2.1.0 for the WooCommerce plugin for WordPress. An online payment system bypass allows orders to be marked as fully paid by assigning an arbitrary bank transaction ID during the payment-details entry step.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Woocommerce Nab Transact | =2.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-11497 is an issue discovered in the NAB Transact extension 2.1.0 for the WooCommerce plugin for WordPress, allowing online payment system bypass.
CVE-2020-11497 has a severity rating of 7.5 (High).
CVE-2020-11497 affects the NAB Transact extension version 2.1.0 for the WooCommerce plugin for WordPress, allowing orders to be marked as fully paid by assigning an arbitrary bank transaction ID during the payment-details entry step.
To fix CVE-2020-11497, update the NAB Transact extension to a version that is not affected.
Yes, you can find the references for CVE-2020-11497 [here](http://packetstormsecurity.com/files/158931/WordPress-NAB-Transact-WooCommerce-2.1.0-Payment-Bypass.html), [here](http://seclists.org/fulldisclosure/2020/Aug/13), and [here](https://www.themissinglink.com.au/security-advisories-cve-2020-11497).