Medium
CVSS 5.3
Overview
The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the order_id parameter in a fetch_order_status action.
The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to vie...
The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the order_id parameter in a fetch_order_status action.
This vulnerability is rated 🟡 MEDIUM.
Recommended actions: