NAB Transact < 2.1.2 - Payment System Bypass

2020-08-20 00:00
Jack Misiura

Strategic Overview

Status
Patched in 2.1.2
Affected PluginNAB Transact
Affected Version< 2.1.2
CVSS7.5High
CVECVE-2020-11497
View all NAB Transact vulnerabilities

Vulnerability Overview

An issue was discovered in the NAB Transact extension 2.1.0 for the WooCommerce plugin for WordPress. An online payment system bypass allows orders to be marked as fully paid by assigning an arbitrary bank transaction ID during the payment-details entry step.

Technical Analysis

REMEDIATION: Update to version 2.1.2, or a newer patched version --- IDENTIFIER: CWE-693 (Protection Mechanism Failure) The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C