PT-2026-69277 · WordPress · Piweb Cancel Order / Refund Request For Woocommerce
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
PiWeb Cancel order / Refund request for WooCommerce WordPress plugin versions prior to 1.3.4.34
Description
Lack of authorization and ownership checks when adding previous order contents to the cart allows unauthenticated users to disclose the contents of other customers' orders. Additionally, an attacker can clear and repopulate the cart of a logged-in user through a crafted link.
Recommendations
Update PiWeb Cancel order / Refund request for WooCommerce WordPress plugin to version 1.3.4.34 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Piweb Cancel Order / Refund Request For Woocommerce