5.3
CVE-2023-4040
- EPSS 0.12%
- Veröffentlicht 18.08.2023 07:15:09
- Zuletzt bearbeitet 21.11.2024 08:34:16
- Quelle security@wordfence.com
- CVE-Watchlists
- Unerledigt
Stripe Payment Plugin for WooCommerce <= 3.7.9 - Missing Authorization to Arbitrary Order Status Modification
The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the eh_callback_handler function in versions up to, and including, 3.7.9. This makes it possible for unauthenticated attackers to modify the order status of arbitrary WooCommerce orders.
Mögliche Gegenmaßnahme
Payment Gateway for Stripe and for WooCommerce: Update to version 3.8.0, or a newer patched version
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
Payment Gateway for Stripe and for WooCommerce
Version
3.7.9
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Webtoffee ≫ Stripe Payment Plugin For Woocommerce SwPlatformwordpress Version < 3.8.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.12% | 0.314 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security@wordfence.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
|