CVE-2020-29156: Medium severity woocommerce vulnerability
The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the orderid parameter in a fetchorderstatus action.
Other sources
The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the orderid parameter in a fetchorderstatus action.
— NVD
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-29156?
CVE-2020-29156 is a vulnerability in the WooCommerce plugin for WordPress that allows remote attackers to view the status of arbitrary orders.
What is the severity of CVE-2020-29156?
The severity of CVE-2020-29156 is medium with a CVSS score of 5.3.
How does CVE-2020-29156 impact WooCommerce?
CVE-2020-29156 allows remote attackers to view the status of orders through the order_id parameter in a fetch_order_status action.
Is there a patch available for CVE-2020-29156?
Yes, WooCommerce plugin version 4.7.0 or later addresses the CVE-2020-29156 vulnerability.
Where can I find more information about CVE-2020-29156?
You can find more information about CVE-2020-29156 in the GitHub repository (https://github.com/Ko-kn3t/CVE-2020-29156) and the official WooCommerce changelog (https://raw.githubusercontent.com/woocommerce/woocommerce/master/changelog.txt).