NAB Transact [woocommerce-gateway-nab-dp] < 2.1.2
unknown
[en] An issue was discovered in the NAB Transact extension 2.1.0 for the WooCommerce plugin for WordPress. An online payment system bypass allows orders to be marked as fully paid by assigning an arbitrary bank transaction ID during the payment-details entry step.
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.2
- Disclosed:
- Aug 26, 2020
CVE-2020-11497 on NVD →
NAB Transact < 2.1.2 - Payment System Bypass
high
An issue was discovered in the NAB Transact extension 2.1.0 for the WooCommerce plugin for WordPress. An online payment system bypass allows orders to be marked as fully paid by assigning an arbitrary bank transaction ID during the payment-details entry step.
- CVSS:
- 7.5
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.2
- Disclosed:
- Aug 20, 2020
CVE-2020-11497 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database