Security Features in NAB Transact WooCommerce - CVE-2020-11497
Published: August 24, 2020
NAB Transact WooCommerce
Tyson Armstrong
Description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the affected plugin does not validate the origin of payment processor status requests. A remote attacker can send a specially crafted request, mark any orders as fully paid and submit arbitrary transaction numbers into the payment records.