CyberRota Analysis
AI-GeneratedThe PiWeb Cancel order / Refund request feature in the WooCommerce WordPress plugin prior to version 1.3.4.34 lacks proper authorization and ownership checks, enabling unauthenticated users to access and disclose the contents of other customers' orders. Additionally, this vulnerability allows attackers to manipulate a logged-in user's cart through crafted links. WordPress site administrators using this plugin should prioritize immediate updates to mitigate potential data exposure and unauthorized cart manipulation.
Original NVD Description
The PiWeb Cancel order / Refund request for WooCommerce WordPress plugin before 1.3.4.34 does not have authorization or ownership checks when adding the contents of a previous order to the cart, allowing unauthenticated users to disclose the contents of other customers' orders, as well as to clear and repopulate a logged in user's cart via a crafted link.